Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 21h2 HIGH 7.8
CVE-2025-21335 KEV

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

Fix: 10.0.19044.5371 / 10.0.19045.5371+
Fix from $1,950 2025-01-14
Windows 10 21h2 HIGH 7.8
CVE-2025-21334 KEV

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

Fix: 10.0.19044.5371 / 10.0.19045.5371+
Fix from $1,950 2025-01-14
Windows 10 21h2 HIGH 7.8
CVE-2025-21333 KEVEPSS 10%

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

Fix: 10.0.19044.5371 / 10.0.19045.5371+
Fix from $1,950 2025-01-14
Endpoint Manager HIGH 7.5
CVE-2024-13161 KEVEPSS 90%

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthen…

Fix: 2022+
Fix from $1,950 2025-01-14
Endpoint Manager HIGH 7.5
CVE-2024-13160 KEVEPSS 91%

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthen…

Fix: 2022+
Fix from $1,950 2025-01-14
Endpoint Manager HIGH 7.5
CVE-2024-13159 KEVEPSS 100%

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthen…

Fix: 2022+
Fix from $1,950 2025-01-14
Fortiproxy CRITICAL 9.8
CVE-2024-55591 KEVEPSS 98%

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy ver…

Fix: 7.0.17 / 7.0.20+
Fix from $2,300 2025-01-14
Sonicos CRITICAL 9.8
CVE-2024-53704 KEVEPSS 95%

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

Fix: after 7.1.1-7058
Fix from $2,300 2025-01-09
Connect Secure CRITICAL 9.0
CVE-2025-0282 KEVEPSS 100%

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for …

Mitigation only
Fix from $2,300 2025-01-08
Controller CRITICAL 9.8
CVE-2024-50603 KEVEPSS 99%

An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used…

Fix: 7.1.4191 / 7.2.4996+
Fix from $2,300 2025-01-08
Vigor300b Firmware CRITICAL 9.8
CVE-2024-12987 KEVEPSS 98%

A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file …

Mitigation only
Fix from $2,300 2024-12-27
Linux Kernel HIGH 7.8
CVE-2024-53197 KEV

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices…

Fix: 4.19.325 / 5.4.287+
Fix from $1,950 2024-12-27
Pan Os HIGH 7.5
CVE-2024-3393 KEVEPSS 29%

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a mali…

Fix: 11.2.3+
Fix from $1,950 2024-12-27
Debian Linux HIGH 7.1
CVE-2024-53150 KEV

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current…

Fix: 5.4.287 / 5.10.231+
Fix from $1,950 2024-12-24
Craft Cms CRITICAL 9.8
CVE-2024-56145 KEVEPSS 97%

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this…

Fix: 3.9.14 / 4.13.2+
Fix from $2,300 2024-12-18
Privileged Remote Access HIGH 7.2
CVE-2024-12686 KEVEPSS 14%

A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrativ…

Fix: after 24.3.1
Fix from $1,950 2024-12-18
Privileged Remote Access CRITICAL 9.8
CVE-2024-12356 KEVEPSS 88%

A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated at…

Fix: after 24.3.1
Fix from $2,300 2024-12-17
Harmony CRITICAL 9.8
CVE-2024-55956 KEVEPSS 94%

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash…

Fix: 5.8.0.24+
Fix from $2,300 2024-12-13
Windows 10 1507 HIGH 7.8
CVE-2024-49138 KEVEPSS 25%

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Fix: 10.0.10240.20857 / 10.0.14393.7606+
Fix from $1,950 2024-12-12
Debian Linux HIGH 7.8
CVE-2024-53104 KEV

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_forma…

Fix: 4.19.324 / 5.4.286+
Fix from $1,950 2024-12-02
Zld CRITICAL 9.8
CVE-2024-11667 KEV

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmwa…

Fix: after 5.38
Fix from $2,300 2024-11-27
Partner Center CRITICAL 9.8
CVE-2024-49035 KEV

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2024-11-26
Projectsend CRITICAL 9.8
CVE-2024-11680 KEVEPSS 92%

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw…

Patch available
Fix from $2,300 2024-11-26
Debian Linux MEDIUM 6.3
CVE-2024-44309 KEVEPSS 23%

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.…

Fix: 2.1.1 / 15.1.1+
Fix from $1,600 2024-11-20
Debian Linux HIGH 8.8
CVE-2024-44308 KEVEPSS 9%

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS…

Fix: 2.1.1 / 15.1.1+
Fix from $1,950 2024-11-20
Debian Linux MEDIUM 5.5
CVE-2024-50302 KEV

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by…

Fix: 3.2 / 4.19.324+
Fix from $1,600 2024-11-19
Agile Product Lifecycle Management HIGH 7.5
CVE-2024-21287 KEV

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The suppor…

Mitigation only
Fix from $1,950 2024-11-18
Pan Os HIGH 7.2
CVE-2024-9474 KEVEPSS 95%

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface …

Fix: 10.1.14 / 10.2.12+
Fix from $1,950 2024-11-18
Pan Os CRITICAL 9.8
CVE-2024-0012 KEVEPSS 100%

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interfac…

Mitigation only
Fix from $2,300 2024-11-18
Mdaemon MEDIUM 6.1
CVE-2024-11182 KEVEPSS 17%

An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img…

Fix: 24.5.1+
Fix from $1,600 2024-11-15