Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2024-57727 KEV |
|
[KEV] Path Traversal in Simplehelp path-traversal (CVE-2024-57727)
path traversal in Simplehelp path-traversal (CVE-2024-57727). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2024-12251 |
|
Command Injection in telerik (CVE-2024-12251)
command injection in telerik (CVE-2024-12251). Successful exploitation can lead to full system takeover.
|
| CVE-2025-21699 |
|
Vulnerability in linux (CVE-2025-21699)
vulnerability in linux (CVE-2025-21699). Successful exploitation can lead to full system takeover.
|
| CVE-2025-21697 |
|
Vulnerability in linux (CVE-2025-21697)
vulnerability in linux (CVE-2025-21697). Successful exploitation can lead to full system takeover.
|
| CVE-2025-21694 |
|
Vulnerability in linux (CVE-2025-21694)
vulnerability in linux (CVE-2025-21694). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-57951 |
|
Use-After-Free in linux (CVE-2024-57951)
vulnerability in linux (CVE-2024-57951). Successful exploitation can lead to full system takeover.
|
| CVE-2024-57952 |
|
Vulnerability in linux (CVE-2024-57952)
vulnerability in linux (CVE-2024-57952). Data can be tampered with by attackers.
|
| CVE-2025-24200 KEV |
|
[KEV] Authorization Flaw in Apple ios-and-ipados (CVE-2025-24200)
vulnerability in Apple ios-and-ipados (CVE-2025-24200). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-41710 KEV |
|
[KEV] Vulnerability in Mitel sip-phones (CVE-2024-41710)
vulnerability in Mitel sip-phones (CVE-2024-41710). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-40891 KEV |
|
[KEV] OS Command Injection in Zyxel dsl-cpe-devices (CVE-2024-40891)
OS command injection in Zyxel dsl-cpe-devices (CVE-2024-40891). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-40890 KEV |
|
[KEV] OS Command Injection in Zyxel dsl-cpe-devices (CVE-2024-40890)
OS command injection in Zyxel dsl-cpe-devices (CVE-2024-40890). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-21418 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2025-21418)
vulnerability in Microsoft windows (CVE-2025-21418). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-21391 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2025-21391)
vulnerability in Microsoft windows (CVE-2025-21391). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-21687 |
|
Out-of-Bounds Read in linux (CVE-2025-21687)
vulnerability in linux (CVE-2025-21687). Successful exploitation can lead to full system takeover.
|
| CVE-2025-21692 |
|
Vulnerability in c (CVE-2025-21692)
vulnerability in c (CVE-2025-21692). Successful exploitation can lead to full system takeover.
|
| CVE-2025-0994 KEV |
|
[KEV] Unsafe Deserialization in Trimble cityworks (CVE-2025-0994)
vulnerability in Trimble cityworks (CVE-2025-0994). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-57523 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2024-57523)
vulnerability in csrf (CVE-2024-57523). Data can be tampered with by attackers.
|
| CVE-2024-21413 KEV |
|
[KEV] Vulnerability in Microsoft office-outlook (CVE-2024-21413)
vulnerability in Microsoft office-outlook (CVE-2024-21413). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-15069 KEV |
|
[KEV] Vulnerability in Sophos xg-firewall (CVE-2020-15069)
vulnerability in Sophos xg-firewall (CVE-2020-15069). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-29574 KEV |
|
[KEV] SQL Injection in Sophos cyberoamos (CVE-2020-29574)
SQL injection in Sophos cyberoamos (CVE-2020-29574). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2022-23748 KEV |
|
[KEV] Vulnerability in Audinate dante-discovery (CVE-2022-23748)
vulnerability in Audinate dante-discovery (CVE-2022-23748). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-0411 KEV |
|
[KEV] Vulnerability in 7-zip (CVE-2025-0411)
vulnerability in 7-zip (CVE-2025-0411). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-20205 |
|
Cross-Site Scripting (XSS) in cisco (CVE-2025-20205)
cross-site scripting in cisco (CVE-2025-20205). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-53104 KEV |
|
[KEV] Out-of-Bounds Write in Linux kernel (CVE-2024-53104)
out-of-bounds write in Linux kernel (CVE-2024-53104). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-19410 KEV |
|
[KEV] Vulnerability in Paessler prtg-network-monitor (CVE-2018-19410)
vulnerability in Paessler prtg-network-monitor (CVE-2018-19410). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-9276 KEV |
|
[KEV] OS Command Injection in Paessler prtg-network-monitor (CVE-2018-9276)
OS command injection in Paessler prtg-network-monitor (CVE-2018-9276). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-29059 KEV |
|
[KEV] Vulnerability in Microsoft net-framework (CVE-2024-29059)
vulnerability in Microsoft net-framework (CVE-2024-29059). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-45195 KEV |
|
[KEV] Vulnerability in Apache ofbiz (CVE-2024-45195)
vulnerability in Apache ofbiz (CVE-2024-45195). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-21682 |
|
Vulnerability in linux (CVE-2025-21682)
vulnerability in linux (CVE-2025-21682). Confidential information can be exposed externally.
|
| CVE-2025-21683 |
|
Vulnerability in linux (CVE-2025-21683)
vulnerability in linux (CVE-2025-21683). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-21669 |
|
Vulnerability in linux (CVE-2025-21669)
vulnerability in linux (CVE-2025-21669). Successful exploitation can lead to full system takeover.
|
| CVE-2025-21678 |
|
Vulnerability in c (CVE-2025-21678)
vulnerability in c (CVE-2025-21678). Successful exploitation can lead to full system takeover.
|
| CVE-2025-21676 |
|
Vulnerability in linux (CVE-2025-21676)
vulnerability in linux (CVE-2025-21676). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-21673 |
|
Vulnerability in linux (CVE-2025-21673)
vulnerability in linux (CVE-2025-21673). Successful exploitation can lead to full system takeover.
|
| CVE-2025-21677 |
|
Vulnerability in c (CVE-2025-21677)
vulnerability in c (CVE-2025-21677). Successful exploitation can lead to full system takeover.
|
| CVE-2024-57948 |
|
Vulnerability in c (CVE-2024-57948)
vulnerability in c (CVE-2024-57948). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-21666 |
|
Vulnerability in linux (CVE-2025-21666)
vulnerability in linux (CVE-2025-21666). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-24085 KEV |
|
[KEV] Use-After-Free in Apple multiple-products (CVE-2025-24085)
vulnerability in Apple multiple-products (CVE-2025-24085). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-48419 |
|
Command Injection in edimax (CVE-2024-48419)
command injection in edimax (CVE-2024-48419). Successful exploitation can lead to full system takeover.
|
| CVE-2024-48420 |
|
Vulnerability in edimax (CVE-2024-48420)
vulnerability in edimax (CVE-2024-48420). Successful exploitation can lead to full system takeover.
|
| CVE-2024-48416 |
|
Vulnerability in edimax (CVE-2024-48416)
vulnerability in edimax (CVE-2024-48416). Successful exploitation can lead to full system takeover.
|
| CVE-2024-48417 |
|
Cross-Site Scripting (XSS) in edimax (CVE-2024-48417)
cross-site scripting in edimax (CVE-2024-48417). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-48418 |
|
Cross-Site Request Forgery (CSRF) in edimax (CVE-2024-48418)
vulnerability in edimax (CVE-2024-48418). Successful exploitation can lead to full system takeover.
|
| CVE-2025-23006 KEV |
|
[KEV] Unsafe Deserialization in Sonicwall sma1000-appliances (CVE-2025-23006)
vulnerability in Sonicwall sma1000-appliances (CVE-2025-23006). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2024-57947 |
|
Vulnerability in linux (CVE-2024-57947)
vulnerability in linux (CVE-2024-57947). Successful exploitation can lead to full system takeover.
|
| CVE-2020-11023 KEV |
|
[KEV] Cross-Site Scripting (XSS) in jquery (CVE-2020-11023)
cross-site scripting in jquery (CVE-2020-11023). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `3.5.0` or later.
|
| CVE-2025-21664 |
|
Vulnerability in linux (CVE-2025-21664)
vulnerability in linux (CVE-2025-21664). Successful exploitation can lead to full system takeover.
|
| CVE-2024-57945 |
|
Out-of-Bounds Read in linux (CVE-2024-57945)
vulnerability in linux (CVE-2024-57945). Successful exploitation can lead to full system takeover.
|
| CVE-2025-21659 |
|
Vulnerability in linux (CVE-2025-21659)
vulnerability in linux (CVE-2025-21659). Data can be tampered with by attackers.
|
| CVE-2025-21661 |
|
Vulnerability in linux (CVE-2025-21661)
vulnerability in linux (CVE-2025-21661). Successful exploitation can lead to full system takeover.
|