CVE Records
Page 7 of 19. 1892 curated CVE records with CVSS, EPSS, and CISA KEV status.
Records
1892 total| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2024-38107 | Windows Power Dependency Coordinator Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.6% | KEV | 2024-08-13 |
| CVE-2024-38106 | Windows Kernel Elevation of Privilege Vulnerability | Microsoft | 7.0 | 6.3% | KEV | 2024-08-13 |
| CVE-2024-38213 | Windows Mark of the Web Security Feature Bypass Vulnerability | Microsoft | 6.5 | 13.6% | KEV | 2024-08-13 |
| CVE-2024-38193 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Microsoft | 7.8 | 28.5% | KEV | 2024-08-13 |
| CVE-2024-38178 | Scripting Engine Memory Corruption Vulnerability | Microsoft | 7.5 | 41.4% | KEV | 2024-08-13 |
| CVE-2024-7694 | TeamT5 ThreatSonar Anti-Ransomware - Arbitrary File Upload | TeamT5 | 7.2 | 1.8% | KEV | 2024-08-12 |
| CVE-2024-41710 | Mitel SIP Phones Argument Injection Vulnerability | - | 6.8 | 41.6% | KEV | 2024-08-12 |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | - | 6.1 | 23.6% | KEV | 2024-08-12 |
| CVE-2024-7399 | Samsung MagicINFO 9 Server Path Traversal Vulnerability | Samsung Electronics | 8.8 | 91.9% | KEV | 2024-08-09 |
| CVE-2024-38856 | Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code | Apache Software Foundation | 8.1 | 99.4% | KEV | 2024-08-05 |
| CVE-2024-42009 | RoundCube Webmail Cross-Site Scripting Vulnerability | - | 9.3 | 82.9% | KEV | 2024-08-05 |
| CVE-2023-45249 | Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability | Acronis | 9.8 | 53.3% | KEV | 2024-07-24 |
| CVE-2024-21182 | Oracle WebLogic Server Unspecified Vulnerability | Oracle Corporation | 7.5 | 74.2% | KEV | 2024-07-16 |
| CVE-2024-5910 | Expedition: Missing Authentication Leads to Admin Account Takeover | Palo Alto Networks | 9.3 | 91.8% | KEV | 2024-07-10 |
| CVE-2024-5217 | Incomplete Input Validation in GlideExpression Script | ServiceNow | 9.8 | 99.6% | KEV | 2024-07-10 |
| CVE-2024-4879 | Jelly Template Injection Vulnerability in ServiceNow UI Macros | ServiceNow | 9.8 | 100.0% | KEV | 2024-07-10 |
| CVE-2024-38094 | Microsoft SharePoint Remote Code Execution Vulnerability | Microsoft | 7.2 | 50.9% | KEV | 2024-07-09 |
| CVE-2024-38112 | Windows MSHTML Platform Spoofing Vulnerability | Microsoft | 7.5 | 84.2% | KEV | 2024-07-09 |
| CVE-2024-38080 | Windows Hyper-V Elevation of Privilege Vulnerability | Microsoft | 7.8 | 7.1% | KEV | 2024-07-09 |
| CVE-2024-39891 | Twilio Authy Information Disclosure Vulnerability | - | 5.3 | 1.7% | KEV | 2024-07-02 |
| CVE-2024-38475 | Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path. | Apache Software Foundation | 9.1 | 100.0% | KEV | 2024-07-01 |
| CVE-2024-20399 | Cisco NX-OS Software CLI Command Injection Vulnerability | Cisco | 6.0 | 4.3% | KEV | 2024-07-01 |
| CVE-2024-36401 | Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver | geoserver | 9.8 | 99.8% | KEV | 2024-07-01 |
| CVE-2024-4885 | WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability | Progress Software Corporation | 9.8 | 99.3% | KEV | 2024-06-25 |
| CVE-2024-37085 | VMware ESXi Authentication Bypass Vulnerability | - | 6.8 | 26.8% | KEV | 2024-06-25 |
| CVE-2024-37079 | Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability | - | 9.8 | 22.4% | KEV | 2024-06-18 |
| CVE-2024-6047 | GeoVision EOL device - OS Command Injection | GeoVision | 9.8 | 10.1% | KEV | 2024-06-17 |
| CVE-2024-32896 | Android Pixel Privilege Escalation Vulnerability | 8.1 | 3.0% | KEV | 2024-06-13 | |
| CVE-2024-34102 | XXE can expose crypt key and other secrets granting full admin access | Adobe | 9.8 | 100.0% | KEV | 2024-06-13 |
| CVE-2024-30088 | Windows Kernel Elevation of Privilege Vulnerability | Microsoft | 7.0 | 68.2% | KEV | 2024-06-11 |
| CVE-2024-35250 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 25.2% | KEV | 2024-06-11 |
| CVE-2024-36971 | net: fix __dst_negative_advice() race | Linux | 7.8 | 2.7% | KEV | 2024-06-10 |
| CVE-2024-4577 | Argument Injection in PHP-CGI | PHP Group | 9.8 | 100.0% | KEV | 2024-06-09 |
| CVE-2024-4610 | Mali GPU Kernel Driver allows improper GPU memory processing operations | Arm Ltd | 7.4 | 0.8% | KEV | 2024-06-07 |
| CVE-2024-37383 | RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability | - | 6.1 | 73.3% | KEV | 2024-06-07 |
| CVE-2024-28995 | SolarWinds Serv-U L Directory Transversal Vulnerability | SolarWinds | 8.6 | 99.6% | KEV | 2024-06-06 |
| CVE-2024-29824 | Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability | Ivanti | 9.6 | 99.9% | KEV | 2024-05-31 |
| CVE-2024-23692 | Rejetto HTTP File Server 2.3m Unauthenticated RCE | Rejetto | 9.8 | 99.5% | KEV | 2024-05-31 |
| CVE-2024-4358 | Registration Authentication Bypass Vulnerability | Progress Software Corporation | 9.8 | 97.5% | KEV | 2024-05-29 |
| CVE-2024-24919 | Information disclosure | checkpoint | 8.6 | 100.0% | KEV | 2024-05-28 |
| CVE-2024-5274 | Google Chromium V8 Type Confusion Vulnerability | 8.3 | 7.5% | KEV | 2024-05-28 | |
| CVE-2024-4978 | Malicious Code in Justice AV Solutions (JAVS) Viewer | Justice AV Solutions | 8.7 | 26.9% | KEV | 2024-05-23 |
| CVE-2024-4947 | Google Chromium V8 Type Confusion Vulnerability | 9.6 | 15.2% | KEV | 2024-05-15 | |
| CVE-2024-30051 | Windows DWM Core Library Elevation of Privilege Vulnerability | Microsoft | 7.8 | 5.6% | KEV | 2024-05-14 |
| CVE-2024-30040 | Windows MSHTML Platform Security Feature Bypass Vulnerability | Microsoft | 8.8 | 3.9% | KEV | 2024-05-14 |
| CVE-2024-4761 | Google Chromium V8 Out-of-Bounds Memory Write Vulnerability | 8.3 | 11.0% | KEV | 2024-05-14 | |
| CVE-2024-4671 | Google Chromium Visuals Use-After-Free Vulnerability | 9.6 | 8.3% | KEV | 2024-05-09 | |
| CVE-2024-32113 | Apache OFBiz: Path traversal leading to RCE | Apache Software Foundation | 9.1 | 99.9% | KEV | 2024-05-08 |
| CVE-2023-50224 | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability | TP-Link | 6.5 | 15.6% | KEV | 2024-05-03 |
| CVE-2024-20359 | Cisco ASA and FTD Privilege Escalation Vulnerability | Cisco | 6.0 | 19.4% | KEV | 2024-04-24 |
| CVE-2024-20353 | Cisco ASA and FTD Denial of Service Vulnerability | Cisco | 8.6 | 70.7% | KEV | 2024-04-24 |
| CVE-2024-4040 | Unauthenticated arbitrary file read and remote code execution in CrushFTP | CrushFTP | 9.8 | 99.5% | KEV | 2024-04-22 |
| CVE-2024-27348 | Apache HugeGraph-Server: Command execution in gremlin | Apache Software Foundation | 9.8 | 99.2% | KEV | 2024-04-22 |
| CVE-2024-3400 | PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect | Palo Alto Networks | 10.0 | 100.0% | KEV | 2024-04-12 |
| CVE-2024-29988 | SmartScreen Prompt Security Feature Bypass Vulnerability | Microsoft | 8.8 | 44.9% | KEV | 2024-04-09 |
| CVE-2024-29748 | Android Pixel Privilege Escalation Vulnerability | 7.8 | 0.7% | KEV | 2024-04-05 | |
| CVE-2024-29745 | Android Pixel Information Disclosure Vulnerability | 5.5 | 0.5% | KEV | 2024-04-05 | |
| CVE-2024-3273 | D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection | D-Link | 7.5 | 100.0% | KEV | 2024-04-04 |
| CVE-2024-3272 | D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials | D-Link | 10.0 | 98.0% | KEV | 2024-04-04 |
| CVE-2024-29059 | .NET Framework Information Disclosure Vulnerability | Microsoft | 7.5 | 98.6% | KEV | 2024-03-22 |
| CVE-2024-20767 | ColdFusion | Improper Access Control (CWE-284) | Adobe | 7.4 | 98.5% | KEV | 2024-03-18 |
| CVE-2024-26169 | Windows Error Reporting Service Elevation of Privilege Vulnerability | Microsoft | 7.8 | 4.0% | KEV | 2024-03-12 |
| CVE-2023-48788 | Fortinet FortiClient EMS SQL Injection Vulnerability | Fortinet | 9.3 | 98.4% | KEV | 2024-03-12 |
| CVE-2024-23296 | Apple Multiple Products Memory Corruption Vulnerability | Apple | 7.8 | 1.4% | KEV | 2024-03-05 |
| CVE-2024-23225 | Apple Multiple Products Memory Corruption Vulnerability | Apple | 7.8 | 1.5% | KEV | 2024-03-05 |
| CVE-2024-27199 | JetBrains TeamCity Relative Path Traversal Vulnerability | JetBrains | 7.3 | 100.0% | KEV | 2024-03-04 |
| CVE-2024-27198 | JetBrains TeamCity Authentication Bypass Vulnerability | JetBrains | 9.8 | 99.9% | KEV | 2024-03-04 |
| CVE-2024-1212 | LoadMaster Pre-Authenticated OS Command Injection | Progress Software | 10.0 | 95.4% | KEV | 2024-02-21 |
| CVE-2024-1709 | Authentication bypass using an alternate path or channel | ConnectWise | 10.0 | 100.0% | KEV | 2024-02-21 |
| CVE-2024-1708 | Improper limitation of a pathname to a restricted directory (“path traversal”) | ConnectWise | 8.4 | 95.4% | KEV | 2024-02-21 |
| CVE-2024-20953 | Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability | Oracle Corporation | 8.8 | 3.9% | KEV | 2024-02-17 |
| CVE-2024-23113 | Fortinet Multiple Products Format String Vulnerability | Fortinet | 9.8 | 61.7% | KEV | 2024-02-15 |
| CVE-2024-21412 | Internet Shortcut Files Security Feature Bypass Vulnerability | Microsoft | 8.1 | 99.4% | KEV | 2024-02-13 |
| CVE-2024-21410 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Microsoft | 9.8 | 12.6% | KEV | 2024-02-13 |
| CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability | Microsoft | 9.8 | 94.7% | KEV | 2024-02-13 |
| CVE-2024-21351 | Windows SmartScreen Security Feature Bypass Vulnerability | Microsoft | 7.6 | 27.8% | KEV | 2024-02-13 |
| CVE-2024-21338 | Windows Kernel Elevation of Privilege Vulnerability | Microsoft | 7.8 | 59.8% | KEV | 2024-02-13 |
| CVE-2024-21762 | Fortinet FortiOS Out-of-Bound Write Vulnerability | Fortinet | 9.6 | 83.4% | KEV | 2024-02-09 |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability | Ivanti | 8.2 | 100.0% | KEV | 2024-01-31 |
| CVE-2024-1086 | Use-after-free in Linux kernel's netfilter: nf_tables component | Linux | 7.8 | 28.1% | KEV | 2024-01-31 |
| CVE-2024-23897 | Jenkins Command Line Interface (CLI) Path Traversal Vulnerability | Jenkins Project | 9.8 | 100.0% | KEV | 2024-01-24 |
| CVE-2024-23222 | Apple Multiple Products WebKit Type Confusion Vulnerability | Apple | 8.8 | 10.6% | KEV | 2024-01-23 |
| CVE-2024-0769 | D-Link DIR-859 HTTP POST Request hedwig.cgi path traversal | D-Link | 5.3 | 82.7% | KEV | 2024-01-21 |
| CVE-2023-6549 | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability | Cloud Software Group | 8.2 | 57.6% | KEV | 2024-01-17 |
| CVE-2023-6548 | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | Cloud Software Group | 5.5 | 3.2% | KEV | 2024-01-17 |
| CVE-2024-0519 | Google Chromium V8 Out-of-Bounds Memory Access Vulnerability | 8.8 | 3.8% | KEV | 2024-01-16 | |
| CVE-2023-22527 | Atlassian Confluence Data Center and Server Template Injection Vulnerability | Atlassian | 10.0 | 100.0% | KEV | 2024-01-16 |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure Command Injection Vulnerability | Ivanti | 9.1 | 100.0% | KEV | 2024-01-12 |
| CVE-2023-46805 | Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability | Ivanti | 8.2 | 100.0% | KEV | 2024-01-12 |
| CVE-2023-7028 | Weak Password Recovery Mechanism for Forgotten Password in GitLab | GitLab | 10.0 | 94.6% | KEV | 2024-01-12 |
| CVE-2023-41974 | Apple iOS and iPadOS Use-After-Free Vulnerability | Apple | 7.8 | 1.9% | KEV | 2024-01-10 |
| CVE-2022-48618 | Apple Multiple Products Memory Corruption Vulnerability | Apple | 7.0 | 0.5% | KEV | 2024-01-09 |
| CVE-2022-2586 | Linux Kernel Use-After-Free Vulnerability | The Linux Kernel Organization | 5.3 | 10.2% | KEV | 2024-01-08 |
| CVE-2023-7101 | Arbitrary Code Execution (ACE) Vulnerability | Douglas Wilson | 7.8 | 19.1% | KEV | 2023-12-24 |
| CVE-2023-7024 | Google Chromium WebRTC Heap Buffer Overflow Vulnerability | 8.8 | 6.7% | KEV | 2023-12-21 | |
| CVE-2023-47565 | Legacy VioStor NVR | QNAP Systems Inc. | 8.0 | 73.3% | KEV | 2023-12-08 |
| CVE-2023-49897 | FXC AE1021, AE1021PE OS Command Injection Vulnerability | FXC Inc. | 8.8 | 50.4% | KEV | 2023-12-06 |
| CVE-2023-44221 | SonicWall SMA100 Appliances OS Command Injection Vulnerability | SonicWall | 7.2 | 76.3% | KEV | 2023-12-05 |
| CVE-2023-6448 | Unitronics VisiLogic uses a default administrative password | Unitronics | 9.8 | 2.1% | KEV | 2023-12-05 |
| CVE-2023-33107 | Integer Overflow or Wraparound in Graphics Linux | Qualcomm, Inc. | 8.4 | 0.9% | KEV | 2023-12-05 |