CVE Records
Page 6 of 19. 1892 curated CVE records with CVSS, EPSS, and CISA KEV status.
Records
1892 total| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2024-48248 | NAKIVO Backup and Replication Absolute Path Traversal Vulnerability | NAKIVO | 8.6 | 94.4% | KEV | 2025-03-04 |
| CVE-2025-24893 | Remote code execution as guest via SolrSearchMacros request in xwiki | xwiki | 9.8 | 99.9% | KEV | 2025-02-20 |
| CVE-2025-24989 | Microsoft Power Pages Elevation of Privilege Vulnerability | Microsoft | 8.2 | 1.6% | KEV | 2025-02-19 |
| CVE-2025-0111 | PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface | Palo Alto Networks | 7.1 | 2.0% | KEV | 2025-02-12 |
| CVE-2025-0108 | PAN-OS: Authentication Bypass in the Management Web Interface | Palo Alto Networks | 8.8 | 98.5% | KEV | 2025-02-12 |
| CVE-2025-21418 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.6% | KEV | 2025-02-11 |
| CVE-2025-21391 | Windows Storage Elevation of Privilege Vulnerability | Microsoft | 7.1 | 2.3% | KEV | 2025-02-11 |
| CVE-2025-24472 | Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | Fortinet | 8.1 | 7.2% | KEV | 2025-02-11 |
| CVE-2025-24016 | Remote code execution in Wazuh server | wazuh | 9.9 | 93.8% | KEV | 2025-02-10 |
| CVE-2025-24200 | Apple iOS and iPadOS Incorrect Authorization Vulnerability | Apple | 6.1 | 4.5% | KEV | 2025-02-10 |
| CVE-2025-0994 | Trimble Cityworks Deserialization Vulnerability | Trimble | 8.6 | 31.3% | KEV | 2025-02-06 |
| CVE-2024-40891 | Zyxel DSL CPE OS Command Injection Vulnerability | Zyxel | 8.8 | 21.5% | KEV | 2025-02-04 |
| CVE-2024-40890 | Zyxel DSL CPE OS Command Injection Vulnerability | Zyxel | 8.8 | 20.7% | KEV | 2025-02-04 |
| CVE-2025-25181 | Advantive VeraCore SQL Injection Vulnerability | Advantive | 5.8 | 55.5% | KEV | 2025-02-03 |
| CVE-2024-57968 | Advantive VeraCore Unrestricted File Upload Vulnerability | Advantive | 9.9 | 32.3% | KEV | 2025-02-03 |
| CVE-2023-52163 | Digiever DS-2105 Pro Missing Authorization Vulnerability | - | 8.8 | 96.9% | KEV | 2025-02-03 |
| CVE-2025-24085 | Apple Multiple Products Use-After-Free Vulnerability | Apple | 10.0 | 17.5% | KEV | 2025-01-27 |
| CVE-2025-0411 | 7-Zip Mark-of-the-Web Bypass Vulnerability | 7-Zip | 7.0 | 67.1% | KEV | 2025-01-25 |
| CVE-2025-23006 | SonicWall SMA1000 Appliances Deserialization Vulnerability | SonicWall | 9.8 | 23.4% | KEV | 2025-01-23 |
| CVE-2025-23209 | Potential RCE with a compromised security key in craft/cms | craftcms | 8.1 | 21.8% | KEV | 2025-01-18 |
| CVE-2024-57728 | SimpleHelp Path Traversal Vulnerability | - | 7.2 | 64.7% | KEV | 2025-01-15 |
| CVE-2024-57727 | SimpleHelp Path Traversal Vulnerability | - | 9.1 | 96.6% | KEV | 2025-01-15 |
| CVE-2024-57726 | SimpleHelp Missing Authorization Vulnerability | - | 9.9 | 66.6% | KEV | 2025-01-15 |
| CVE-2025-21334 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.6% | KEV | 2025-01-14 |
| CVE-2025-21333 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Microsoft | 7.8 | 10.0% | KEV | 2025-01-14 |
| CVE-2025-21335 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.4% | KEV | 2025-01-14 |
| CVE-2024-13159 | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | Ivanti | 9.8 | 100.0% | KEV | 2025-01-14 |
| CVE-2024-13160 | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | Ivanti | 9.8 | 91.2% | KEV | 2025-01-14 |
| CVE-2024-13161 | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | Ivanti | 9.8 | 90.1% | KEV | 2025-01-14 |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | Fortinet | 9.6 | 94.1% | KEV | 2025-01-14 |
| CVE-2024-53704 | SonicWall SonicOS SSLVPN Improper Authentication Vulnerability | SonicWall | 8.2 | 95.1% | KEV | 2025-01-09 |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | Ivanti | 9.0 | 100.0% | KEV | 2025-01-08 |
| CVE-2024-50603 | Aviatrix Controllers OS Command Injection Vulnerability | Aviatrix | 10.0 | 98.5% | KEV | 2025-01-08 |
| CVE-2024-12987 | DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection | DrayTek | 7.5 | 98.1% | KEV | 2024-12-27 |
| CVE-2024-53197 | ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices | Linux | 7.8 | 3.6% | KEV | 2024-12-27 |
| CVE-2024-3393 | PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet | Palo Alto Networks | 8.7 | 28.6% | KEV | 2024-12-27 |
| CVE-2024-53150 | ALSA: usb-audio: Fix out of bounds reads when finding clock sources | Linux | 7.1 | 1.4% | KEV | 2024-12-24 |
| CVE-2024-56145 | RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms | craftcms | 9.3 | 97.4% | KEV | 2024-12-18 |
| CVE-2024-12686 | Command Injection vulnerability in Remote Support(RS) & Privilege Remote Access (PRA) | BeyondTrust | 6.6 | 13.7% | KEV | 2024-12-18 |
| CVE-2024-12356 | Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA) | BeyondTrust | 9.8 | 87.3% | KEV | 2024-12-17 |
| CVE-2024-55956 | Cleo Multiple Products Unauthenticated File Upload Vulnerability | - | 9.8 | 94.0% | KEV | 2024-12-13 |
| CVE-2024-49138 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 26.2% | KEV | 2024-12-10 |
| CVE-2024-55550 | Mitel MiCollab Path Traversal Vulnerability | - | 4.4 | 38.2% | KEV | 2024-12-10 |
| CVE-2024-53104 | media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format | Linux | 7.8 | 3.4% | KEV | 2024-12-02 |
| CVE-2024-11667 | Zyxel Multiple Firewalls Path Traversal Vulnerability | Zyxel | 7.5 | 2.9% | KEV | 2024-11-27 |
| CVE-2024-49035 | Partner.Microsoft.Com Elevation of Privilege Vulnerability | Microsoft | 8.7 | 1.3% | KEV | 2024-11-26 |
| CVE-2024-11680 | ProjectSend Unauthenticated Configuration Modification | ProjectSend | 9.8 | 91.7% | KEV | 2024-11-26 |
| CVE-2024-44309 | Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability | Apple | 6.3 | 22.6% | KEV | 2024-11-19 |
| CVE-2024-44308 | Apple Multiple Products Code Execution Vulnerability | Apple | 8.8 | 10.1% | KEV | 2024-11-19 |
| CVE-2024-50302 | HID: core: zero-initialize the report buffer | Linux | 5.5 | 0.8% | KEV | 2024-11-19 |
| CVE-2024-21287 | Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability | Oracle Corporation | 7.5 | 1.7% | KEV | 2024-11-18 |
| CVE-2024-9474 | PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface | Palo Alto Networks | 6.9 | 94.7% | KEV | 2024-11-18 |
| CVE-2024-0012 | PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) | Palo Alto Networks | 9.3 | 99.8% | KEV | 2024-11-18 |
| CVE-2024-11182 | Stored XSS vulnerability in MDaemon Email Server | MDaemon | 5.3 | 17.6% | KEV | 2024-11-15 |
| CVE-2024-11120 | GeoVision EOL devices - OS Command Injection | GeoVision | 9.8 | 28.4% | KEV | 2024-11-15 |
| CVE-2024-43093 | Android Framework Privilege Escalation Vulnerability | 7.3 | 0.7% | KEV | 2024-11-13 | |
| CVE-2024-8069 | Limited remote code execution with privilege of a NetworkService Account access | Citrix Session Recording | 5.1 | 14.6% | KEV | 2024-11-12 |
| CVE-2024-49039 | Windows Task Scheduler Elevation of Privilege Vulnerability | Microsoft | 8.8 | 14.2% | KEV | 2024-11-12 |
| CVE-2024-43451 | NTLM Hash Disclosure Spoofing Vulnerability | Microsoft | 6.5 | 84.1% | KEV | 2024-11-12 |
| CVE-2024-8068 | Privilege escalation to NetworkService Account access | Citrix | 5.1 | 3.5% | KEV | 2024-11-12 |
| CVE-2024-51567 | CyberPanel Incorrect Default Permissions Vulnerability | - | 10.0 | 86.6% | KEV | 2024-10-29 |
| CVE-2024-51378 | CyberPanel Incorrect Default Permissions Vulnerability | - | 10.0 | 94.7% | KEV | 2024-10-29 |
| CVE-2024-50623 | Cleo Multiple Products Unrestricted File Upload Vulnerability | - | 9.8 | 98.6% | KEV | 2024-10-27 |
| CVE-2024-20481 | Cisco ASA and FTD Denial-of-Service Vulnerability | Cisco | 5.8 | 15.8% | KEV | 2024-10-23 |
| CVE-2024-47575 | Fortinet FortiManager Missing Authentication Vulnerability | Fortinet | 9.8 | 94.8% | KEV | 2024-10-23 |
| CVE-2024-41713 | Mitel MiCollab Path Traversal Vulnerability | - | 9.1 | 98.1% | KEV | 2024-10-21 |
| CVE-2024-9537 | ScienceLogic SL1 unspecified vulnerability | ScienceLogic | 9.8 | 3.8% | KEV | 2024-10-18 |
| CVE-2024-9465 | Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure | Palo Alto Networks | 9.2 | 99.6% | KEV | 2024-10-09 |
| CVE-2024-9463 | Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure | Palo Alto Networks | 9.9 | 98.5% | KEV | 2024-10-09 |
| CVE-2024-9680 | Mozilla Firefox Use-After-Free Vulnerability | Mozilla | 9.8 | 23.2% | KEV | 2024-10-09 |
| CVE-2024-43572 | Microsoft Management Console Remote Code Execution Vulnerability | Microsoft | 7.8 | 66.7% | KEV | 2024-10-08 |
| CVE-2024-43468 | Microsoft Configuration Manager Remote Code Execution Vulnerability | Microsoft | 9.8 | 80.9% | KEV | 2024-10-08 |
| CVE-2024-43573 | Windows MSHTML Platform Spoofing Vulnerability | Microsoft | 6.5 | 46.1% | KEV | 2024-10-08 |
| CVE-2024-9380 | Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability | Ivanti | 7.2 | 59.7% | KEV | 2024-10-08 |
| CVE-2024-9379 | Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability | Ivanti | 6.5 | 43.8% | KEV | 2024-10-08 |
| CVE-2024-43047 | Use After Free in DSP Service | Qualcomm, Inc. | 7.8 | 0.7% | KEV | 2024-10-07 |
| CVE-2024-45519 | Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability | - | 10.0 | 99.9% | KEV | 2024-10-02 |
| CVE-2024-8963 | Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability | Ivanti | 9.4 | 98.6% | KEV | 2024-09-19 |
| CVE-2024-8957 | PTZOptics NDI and SDI Cameras Command Injection via NTP Address Configuration | PTZOptics | 7.2 | 79.7% | KEV | 2024-09-17 |
| CVE-2024-8956 | PTZOptics NDI and SDI Cameras /cgi-bin/param.cgi Insufficient Authentication | PTZOptics | 9.1 | 58.8% | KEV | 2024-09-17 |
| CVE-2024-38813 | Privilege escalation vulnerability | - | 7.5 | 17.4% | KEV | 2024-09-17 |
| CVE-2024-38812 | Heap-overflow vulnerability | - | 9.8 | 54.6% | KEV | 2024-09-17 |
| CVE-2024-8190 | Ivanti Cloud Services Appliance OS Command Injection Vulnerability | Ivanti | 7.2 | 88.5% | KEV | 2024-09-10 |
| CVE-2024-43461 | Windows MSHTML Platform Spoofing Vulnerability | Microsoft | 8.8 | 54.5% | KEV | 2024-09-10 |
| CVE-2024-38226 | Microsoft Publisher Security Feature Bypass Vulnerability | Microsoft | 7.3 | 2.7% | KEV | 2024-09-10 |
| CVE-2024-38217 | Windows Mark of the Web Security Feature Bypass Vulnerability | Microsoft | 5.4 | 10.0% | KEV | 2024-09-10 |
| CVE-2024-38014 | Windows Installer Elevation of Privilege Vulnerability | Microsoft | 7.8 | 6.3% | KEV | 2024-09-10 |
| CVE-2024-40711 | Veeam Backup and Replication Deserialization Vulnerability | Veeam | 9.8 | 90.4% | KEV | 2024-09-07 |
| CVE-2024-20439 | Cisco Smart Licensing Utility Static Credential Vulnerability | Cisco | 9.8 | 97.1% | KEV | 2024-09-04 |
| CVE-2024-45195 | Apache OFBiz: Confused controller-view authorization logic (forced browsing) | Apache Software Foundation | 9.8 | 100.0% | KEV | 2024-09-04 |
| CVE-2024-6670 | WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability | Progress Software Corporation | 9.8 | 93.0% | KEV | 2024-08-29 |
| CVE-2024-40766 | SonicWall SonicOS Improper Access Control Vulnerability | SonicWall | 9.3 | 18.4% | KEV | 2024-08-23 |
| CVE-2024-39717 | Versa Director Dangerous File Type Upload Vulnerability | Versa | 6.6 | 4.0% | KEV | 2024-08-22 |
| CVE-2024-28987 | SolarWinds Web Help Desk Hardcoded Credential Vulnerability | SolarWinds | 9.1 | 93.3% | KEV | 2024-08-21 |
| CVE-2024-7971 | Google Chromium V8 Type Confusion Vulnerability | 8.8 | 21.1% | KEV | 2024-08-21 | |
| CVE-2024-7965 | Google Chromium V8 Inappropriate Implementation Vulnerability | 8.8 | 18.5% | KEV | 2024-08-21 | |
| CVE-2024-7262 | Arbitrary Code Execution in WPS Office | Kingsoft | 9.3 | 2.9% | KEV | 2024-08-15 |
| CVE-2024-28986 | SolarWinds Web Help Desk Java Deserialization Remote Code Execution Vulnerability | SolarWinds | 9.8 | 84.6% | KEV | 2024-08-13 |
| CVE-2024-7593 | Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability | Ivanti | 9.8 | 100.0% | KEV | 2024-08-13 |
| CVE-2024-38189 | Microsoft Project Remote Code Execution Vulnerability | Microsoft | 8.8 | 8.2% | KEV | 2024-08-13 |