Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gv Vs12 Firmware CRITICAL 9.8
CVE-2024-11120 KEVEPSS 29%

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject a…

Mitigation only
Fix from $2,300 2024-11-15
Android HIGH 7.3
CVE-2024-43093 KEV

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive direc…

Patch available
Fix from $1,950 2024-11-13
Session Recording HIGH 8.0
CVE-2024-8069 KEVEPSS 15%

Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user …

Fix: 2407+
Fix from $1,950 2024-11-12
Session Recording HIGH 8.0
CVE-2024-8068 KEV

Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Activ…

Fix: 2407+
Fix from $1,950 2024-11-12
Windows 10 1507 HIGH 8.8
CVE-2024-49039 KEVEPSS 14%

Windows Task Scheduler Elevation of Privilege Vulnerability

Fix: 10.0.10240.20826 / 10.0.14393.7515+
Fix from $1,950 2024-11-12
Windows 10 1507 MEDIUM 6.5
CVE-2024-43451 KEVEPSS 82%

NTLM Hash Disclosure Spoofing Vulnerability

Fix: 10.0.10240.20826 / 10.0.14393.7515+
Fix from $1,600 2024-11-12
Cyberpanel CRITICAL 9.8
CVE-2024-51567 KEVEPSS 87%

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute …

Fix: 2.3.8+
Fix from $2,300 2024-10-29
Cyberpanel CRITICAL 9.8
CVE-2024-51378 KEVEPSS 95%

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and e…

Fix: 2.3.8+
Fix from $2,300 2024-10-29
Harmony CRITICAL 9.8
CVE-2024-50623 KEVEPSS 99%

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could …

Fix: 5.8.0.21+
Fix from $2,300 2024-10-28
Secure Firewall Threat Defense MEDIUM 5.8
CVE-2024-20481 KEVEPSS 16%

A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)…

Mitigation only
Fix from $1,600 2024-10-23
Fortimanager CRITICAL 9.8
CVE-2024-47575 KEVEPSS 95%

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManage…

Fix: 6.2.13 / 6.4.15+
Fix from $2,300 2024-10-23
Micollab CRITICAL 9.1
CVE-2024-41713 KEVEPSS 98%

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated att…

Fix: after 9.8.1.201
Fix from $2,300 2024-10-21
Sl1 CRITICAL 9.8
CVE-2024-9537 KEV

ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vul…

Fix: 12.1.3 / 12.2.3+
Fix from $2,300 2024-10-18
Expedition CRITICAL 9.1
CVE-2024-9465 KEVEPSS 100%

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as pa…

Fix: 1.2.96+
Fix from $2,300 2024-10-09
Expedition HIGH 7.5
CVE-2024-9463 KEVEPSS 98%

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Exp…

Fix: 1.2.96+
Fix from $1,950 2024-10-09
Firefox CRITICAL 9.8
CVE-2024-9680 KEVEPSS 23%

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of t…

Fix: 115.16.0 / 115.16.1+
Fix from $2,300 2024-10-09
Windows 10 1507 HIGH 8.1
CVE-2024-43573 KEVEPSS 44%

Windows MSHTML Platform Spoofing Vulnerability

Fix: 10.0.10240.20796 / 10.0.14393.7428+
Fix from $1,950 2024-10-08
Windows 10 1507 HIGH 7.8
CVE-2024-43572 KEVEPSS 67%

Microsoft Management Console Remote Code Execution Vulnerability

Fix: 10.0.10240.20796 / 10.0.14393.7428+
Fix from $1,950 2024-10-08
Configuration Manager 2403 CRITICAL 9.8
CVE-2024-43468 KEVEPSS 61%

Microsoft Configuration Manager Remote Code Execution Vulnerability

No fix yet
Fix from $2,300 2024-10-08
Endpoint Manager Cloud Services Appliance HIGH 7.2
CVE-2024-9380 KEVEPSS 63%

An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin p…

Fix: 5.0.2+
Fix from $1,950 2024-10-08
Endpoint Manager Cloud Services Appliance HIGH 7.2
CVE-2024-9379 KEVEPSS 43%

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitra…

Fix: 5.0.2+
Fix from $1,950 2024-10-08
Fastconnect 6700 Firmware HIGH 7.8
CVE-2024-43047 KEV

Memory corruption while maintaining memory maps of HLOS memory.

Patch available
Fix from $1,950 2024-10-07
Zimbra Collaboration Suite CRITICAL 9.8
CVE-2024-45519 KEVEPSS 100%

The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 somet…

Fix: 8.8.15 / 10.0.9+
Fix from $2,300 2024-10-02
Endpoint Manager Cloud Services Appliance CRITICAL 9.1
CVE-2024-8963 KEVEPSS 99%

Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

Mitigation only
Fix from $2,300 2024-09-19
Pt30x Sdi Firmware HIGH 7.2
CVE-2024-8957 KEVEPSS 82%

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_a…

Fix: 6.3.40+
Fix from $1,950 2024-09-17
Pt30x Sdi Firmware CRITICAL 9.1
CVE-2024-8956 KEVEPSS 61%

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authent…

Fix: 6.3.40+
Fix from $2,300 2024-09-17
Cloud Foundation CRITICAL 9.8
CVE-2024-38813 KEVEPSS 17%

The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerabil…

Fix: 5.2+
Fix from $2,300 2024-09-17
Cloud Foundation CRITICAL 9.8
CVE-2024-38812 KEVEPSS 55%

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCen…

Fix: 5.2+
Fix from $2,300 2024-09-17
Cloud Services Appliance HIGH 7.2
CVE-2024-8190 KEVEPSS 89%

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to …

Mitigation only
Fix from $1,950 2024-09-10
Windows 10 1507 HIGH 8.8
CVE-2024-43461 KEVEPSS 52%

Windows MSHTML Platform Spoofing Vulnerability

Fix: 10.0.10240.20766 / 10.0.14393.7336+
Fix from $1,950 2024-09-10