Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2023-45249 KEV |
|
[KEV] Vulnerability in Acronis cyber-infrastructure-aci (CVE-2023-45249)
vulnerability in Acronis cyber-infrastructure-aci (CVE-2023-45249). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-5217 KEV |
|
[KEV] Vulnerability in Servicenow utah (CVE-2024-5217)
vulnerability in Servicenow utah (CVE-2024-5217). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-4879 KEV |
|
[KEV] Vulnerability in Servicenow utah (CVE-2024-4879)
vulnerability in Servicenow utah (CVE-2024-4879). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-39891 KEV |
|
[KEV] Vulnerability in Twilio authy (CVE-2024-39891)
vulnerability in Twilio authy (CVE-2024-39891). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2012-4792 KEV |
|
[KEV] Use-After-Free in Microsoft internet-explorer (CVE-2012-4792)
vulnerability in Microsoft internet-explorer (CVE-2012-4792). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-22948 KEV |
|
[KEV] Vulnerability in Vmware vcenter-server (CVE-2022-22948)
vulnerability in Vmware vcenter-server (CVE-2022-22948). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-28995 KEV |
|
[KEV] Path Traversal in Solarwinds serv-u (CVE-2024-28995)
path traversal in Solarwinds serv-u (CVE-2024-28995). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-34102 KEV |
|
[KEV] XXE (XML External Entity) in Adobe commerce-and-magento-open-source (CVE-2024-34102)
vulnerability in Adobe commerce-and-magento-open-source (CVE-2024-34102). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-36401 KEV |
|
[KEV] Vulnerability in Osgeo geoserver (CVE-2024-36401)
vulnerability in Osgeo geoserver (CVE-2024-36401). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-3596 |
|
Vulnerability in freeradius (CVE-2024-3596)
vulnerability in freeradius (CVE-2024-3596). Successful exploitation can lead to full system takeover.
|
| CVE-2024-4944 |
|
Command Injection in privilege-escalation (CVE-2024-4944)
command injection in privilege-escalation (CVE-2024-4944). Successful exploitation can lead to full system takeover.
|
| CVE-2024-38080 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2024-38080)
vulnerability in Microsoft windows (CVE-2024-38080). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-38112 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2024-38112)
vulnerability in Microsoft windows (CVE-2024-38112). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-23692 KEV |
|
[KEV] Vulnerability in Rejetto http-file-server (CVE-2024-23692)
vulnerability in Rejetto http-file-server (CVE-2024-23692). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2024-20399 KEV |
|
[KEV] OS Command Injection in Cisco nx-os (CVE-2024-20399)
OS command injection in Cisco nx-os (CVE-2024-20399). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-6387 |
|
Vulnerability in sonicwall (CVE-2024-6387)
vulnerability in sonicwall (CVE-2024-6387). Successful exploitation can lead to full system takeover.
|
| CVE-2022-2586 KEV |
|
[KEV] Use-After-Free in Linux kernel (CVE-2022-2586)
vulnerability in Linux kernel (CVE-2022-2586). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-13965 KEV |
|
[KEV] Vulnerability in Roundcube webmail (CVE-2020-13965)
vulnerability in Roundcube webmail (CVE-2020-13965). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-24816 KEV |
|
[KEV] Code Injection in Osgeo jai-ext (CVE-2022-24816)
code injection in Osgeo jai-ext (CVE-2022-24816). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-38082 |
|
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
|
| CVE-2024-38093 |
|
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
|
| CVE-2024-30057 |
|
Microsoft Edge for iOS Spoofing Vulnerability
Microsoft Edge for iOS Spoofing Vulnerability
|
| CVE-2024-4358 KEV |
|
[KEV] Vulnerability in Progress telerik-report-server (CVE-2024-4358)
vulnerability in Progress telerik-report-server (CVE-2024-4358). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-32896 KEV |
|
[KEV] Vulnerability in Android pixel (CVE-2024-32896)
vulnerability in Android pixel (CVE-2024-32896). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-26169 KEV |
|
[KEV] Privilege Escalation in Microsoft windows (CVE-2024-26169)
vulnerability in Microsoft windows (CVE-2024-26169). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-36265 |
|
Authorization Flaw in apache-submarine (CVE-2024-36265)
vulnerability in apache-submarine (CVE-2024-36265). Successful exploitation can lead to full system takeover.
|
| CVE-2024-4577 KEV |
|
[KEV] OS Command Injection in Php group libphp (CVE-2024-4577)
OS command injection in Php group libphp (CVE-2024-4577). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `8.1.29, 8.2.20, 8.3.8` or later.
|
| CVE-2024-4610 KEV |
|
[KEV] Use-After-Free in Arm :unknown: (CVE-2024-4610)
vulnerability in Arm :unknown: (CVE-2024-4610). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `SoCVersion:2024-07-05` or later.
|
| CVE-2024-30104 |
|
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
|
| CVE-2024-30101 |
|
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
|
| CVE-2024-30103 |
|
Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
|
| CVE-2017-3506 KEV |
|
[KEV] OS Command Injection in Oracle weblogic-server (CVE-2017-3506)
OS command injection in Oracle weblogic-server (CVE-2017-3506). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-1086 KEV |
|
[KEV] Use-After-Free in Linux kernel (CVE-2024-1086)
vulnerability in Linux kernel (CVE-2024-1086). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2024-24919 KEV |
|
[KEV] Information Disclosure in Check point check-point (CVE-2024-24919)
vulnerability in Check point check-point (CVE-2024-24919). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2024-4978 KEV |
|
[KEV] Vulnerability in Justice av solutions justice-av-solutions (CVE-2024-4978)
vulnerability in Justice av solutions justice-av-solutions (CVE-2024-4978). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-5274 KEV |
|
[KEV] Vulnerability in Google chromium-v8 (CVE-2024-5274)
vulnerability in Google chromium-v8 (CVE-2024-5274). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-47544 |
|
Vulnerability in apache (CVE-2021-47544)
vulnerability in apache (CVE-2021-47544). Successful exploitation can lead to full system takeover.
|
| CVE-2020-17519 KEV |
|
[KEV] Vulnerability in Apache flink (CVE-2020-17519)
vulnerability in Apache flink (CVE-2020-17519). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2024-4947 KEV |
|
[KEV] Vulnerability in Google chromium-v8 (CVE-2024-4947)
vulnerability in Google chromium-v8 (CVE-2024-4947). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-43208 KEV |
|
[KEV] Unsafe Deserialization in Nextgen healthcare nextgen-healthcare (CVE-2023-43208)
vulnerability in Nextgen healthcare nextgen-healthcare (CVE-2023-43208). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-40655 KEV |
|
[KEV] Authorization Flaw in D-link dir-605-router (CVE-2021-40655)
vulnerability in D-link dir-605-router (CVE-2021-40655). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2014-100005 KEV |
|
[KEV] Cross-Site Request Forgery (CSRF) in D-link dir-600-router (CVE-2014-100005)
vulnerability in D-link dir-600-router (CVE-2014-100005). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-4761 KEV |
|
[KEV] Out-of-Bounds Write in Google chromium-v8 (CVE-2024-4761)
out-of-bounds write in Google chromium-v8 (CVE-2024-4761). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-4367 |
|
Vulnerability in pdfjs-dist (CVE-2024-4367)
vulnerability in pdfjs-dist (CVE-2024-4367). Successful exploitation can lead to full system takeover. Exploitable via ``isEvalSupported``. Mitigation: upgrade to `4.2.67` or later.
|
| CVE-2023-45583 |
|
Vulnerability in fortinet (CVE-2023-45583)
vulnerability in fortinet (CVE-2023-45583). Successful exploitation can lead to full system takeover.
|
| CVE-2023-36640 |
|
Vulnerability in fortinet (CVE-2023-36640)
vulnerability in fortinet (CVE-2023-36640). Successful exploitation can lead to full system takeover.
|
| CVE-2024-30040 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2024-30040)
vulnerability in Microsoft windows (CVE-2024-30040). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-30051 KEV |
|
[KEV] Vulnerability in Microsoft dwm-core-library (CVE-2024-30051)
vulnerability in Microsoft dwm-core-library (CVE-2024-30051). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-4671 KEV |
|
[KEV] Use-After-Free in Google chromium (CVE-2024-4671)
vulnerability in Google chromium (CVE-2024-4671). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2024-33775 |
|
Privilege Escalation in nagios (CVE-2024-33775)
vulnerability in nagios (CVE-2024-33775). Successful exploitation can lead to full system takeover.
|