Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Office 2019 HIGH 7.3
CVE-2024-38226 KEV

Microsoft Publisher Security Feature Bypass Vulnerability

Patch available
Fix from $1,950 2024-09-10
Windows 10 1507 MEDIUM 5.4
CVE-2024-38217 KEVEPSS 10%

Windows Mark of the Web Security Feature Bypass Vulnerability

Fix: 10.0.10240.20766 / 10.0.14393.7336+
Fix from $1,600 2024-09-10
Windows 10 1507 HIGH 7.8
CVE-2024-38014 KEVEPSS 6%

Windows Installer Elevation of Privilege Vulnerability

Fix: 10.0.10240.20766 / 10.0.14393.7336+
Fix from $1,950 2024-09-10
Veeam Backup \& Replication CRITICAL 9.8
CVE-2024-40711 KEVEPSS 90%

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

Fix: 12.2.0.334+
Fix from $2,300 2024-09-07
Smart License Utility CRITICAL 9.8
CVE-2024-20439 KEVEPSS 92%

A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a sta…

Fix: 2.3.0+
Fix from $2,300 2024-09-04
Ofbiz HIGH 7.5
CVE-2024-45195 KEVEPSS 100%

Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrad…

Fix: 18.12.16+
Fix from $1,950 2024-09-04
Whatsup Gold CRITICAL 9.8
CVE-2024-6670 KEVEPSS 95%

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted p…

Fix: 24.0+
Fix from $2,300 2024-08-29
Sonicos CRITICAL 9.8
CVE-2024-40766 KEVEPSS 18%

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource…

Fix: 5.9.2.14-13o / 6.5.2.8-2n+
Fix from $2,300 2024-08-23
Versa Director HIGH 7.2
CVE-2024-39717 KEV

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with …

Mitigation only
Fix from $1,950 2024-08-22
Web Help Desk CRITICAL 9.1
CVE-2024-28987 KEVEPSS 93%

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access inter…

Fix: 12.8.3+
Fix from $2,300 2024-08-21
Chrome CRITICAL 9.6
CVE-2024-7971 KEVEPSS 21%

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium …

Fix: 128.0.2739.42 / 128.0.6613.84+
Fix from $2,300 2024-08-21
Chrome HIGH 8.8
CVE-2024-7965 KEVEPSS 19%

Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 128.0.2739.42 / 128.0.6613.84+
Fix from $1,950 2024-08-21
Wps Office HIGH 7.8
CVE-2024-7262 KEV

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows al…

Fix: 12.2.0.16412+
Fix from $1,950 2024-08-15
Web Help Desk CRITICAL 9.8
CVE-2024-28986 KEVEPSS 85%

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an…

Fix: after 12.8.2
Fix from $2,300 2024-08-13
Virtual Traffic Manager CRITICAL 9.8
CVE-2024-7593 KEVEPSS 100%

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker t…

Patch available
Fix from $2,300 2024-08-13
Windows 10 1507 MEDIUM 6.5
CVE-2024-38213 KEVEPSS 14%

Windows Mark of the Web Security Feature Bypass Vulnerability

Fix: 10.0.10240.20680 / 10.0.14393.7070+
Fix from $1,600 2024-08-13
Windows 10 1507 HIGH 7.8
CVE-2024-38193 KEVEPSS 27%

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Fix: 10.0.10240.20751 / 10.0.14393.7259+
Fix from $1,950 2024-08-13
365 Apps HIGH 8.8
CVE-2024-38189 KEVEPSS 8%

Microsoft Project Remote Code Execution Vulnerability

Fix: 16.0.5461.1001+
Fix from $1,950 2024-08-13
Windows 10 1507 HIGH 7.5
CVE-2024-38178 KEVEPSS 41%

Scripting Engine Memory Corruption Vulnerability

Fix: 10.0.10240.20751 / 10.0.14393.7259+
Fix from $1,950 2024-08-13
Windows 10 1507 HIGH 7.8
CVE-2024-38107 KEV

Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

Fix: 10.0.10240.20751 / 10.0.14393.7259+
Fix from $1,950 2024-08-13
Windows 10 1507 HIGH 7.0
CVE-2024-38106 KEVEPSS 6%

Windows Kernel Elevation of Privilege Vulnerability

Fix: 10.0.10240.20751 / 10.0.14393.7259+
Fix from $1,950 2024-08-13
6970 Firmware HIGH 7.2
CVE-2024-41710 KEVEPSS 42%

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.13…

Fix: after 6.4.0.136
Fix from $1,950 2024-08-12
Collaboration MEDIUM 6.1
CVE-2024-27443 KEVEPSS 24%

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature o…

Fix: 10.0.7+
Fix from $1,600 2024-08-12
Threatsonar Anti Ransomware HIGH 7.2
CVE-2024-7694 KEV

ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on …

Fix: 3.5.0+
Fix from $1,950 2024-08-12
Magicinfo 9 Server CRITICAL 9.8
CVE-2024-7399 KEVEPSS 92%

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to wr…

Fix: 21.1050.0+
Fix from $2,300 2024-08-12
Webmail CRITICAL 9.3
CVE-2024-42009 KEVEPSS 80%

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim…

Fix: 1.5.8 / 1.6.8+
Fix from $2,300 2024-08-05
Ofbiz CRITICAL 9.8
CVE-2024-38856 KEVEPSS 99%

Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to versi…

Fix: 18.12.15+
Fix from $2,300 2024-08-05
Cyber Infrastructure CRITICAL 9.8
CVE-2023-45249 KEVEPSS 53%

Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-…

Fix: 5.0.1-61 / 5.1.1-71+
Fix from $2,300 2024-07-24
Weblogic Server HIGH 7.5
CVE-2024-21182 KEVEPSS 50%

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…

Mitigation only
Fix from $1,950 2024-07-16
Expedition CRITICAL 9.8
CVE-2024-5910 KEVEPSS 92%

Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with n…

Fix: 1.2.92+
Fix from $2,300 2024-07-10