Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Servicenow CRITICAL 9.8
CVE-2024-5217 KEVEPSS 100%

ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. Th…

Mitigation only
Fix from $2,300 2024-07-10
Servicenow CRITICAL 9.8
CVE-2024-4879 KEVEPSS 100%

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerabili…

Mitigation only
Fix from $2,300 2024-07-10
Windows 10 1507 HIGH 7.5
CVE-2024-38112 KEVEPSS 84%

Windows MSHTML Platform Spoofing Vulnerability

Fix: 10.0.10240.20710 / 10.0.14393.7159+
Fix from $1,950 2024-07-09
Sharepoint Server HIGH 7.2
CVE-2024-38094 KEVEPSS 51%

Microsoft SharePoint Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-07-09
Windows 11 21h2 HIGH 7.8
CVE-2024-38080 KEVEPSS 7%

Windows Hyper-V Elevation of Privilege Vulnerability

Fix: 10.0.20348.2582 / 10.0.22000.3079+
Fix from $1,950 2024-07-09
Authy MEDIUM 5.3
CVE-2024-39891 KEV

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain …

Fix: 25.1.0 / 26.1.0+
Fix from $1,600 2024-07-02
HTTP Server CRITICAL 9.1
CVE-2024-38475 KEVEPSS 100%

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are p…

Fix: 2.4.60 / 10.2.1.14-75sv+
Fix from $2,300 2024-07-01
Nx Os MEDIUM 6.7
CVE-2024-20399 KEV

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary …

Mitigation only
Fix from $1,600 2024-07-01
Geoserver CRITICAL 9.8
CVE-2024-36401 KEVEPSS 100%

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multipl…

Fix: 2.22.6 / 2.23.6+
Fix from $2,300 2024-07-01
Whatsup Gold CRITICAL 9.8
CVE-2024-4885 KEVEPSS 99%

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.Exp…

Fix: 23.1.3+
Fix from $2,300 2024-06-25
Cloud Foundation HIGH 7.2
CVE-2024-37085 KEVEPSS 26%

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access…

Fix: 5.2+
Fix from $1,950 2024-06-25
Cloud Foundation CRITICAL 9.8
CVE-2024-37079 KEVEPSS 22%

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter …

Fix: 5.2+
Fix from $2,300 2024-06-18
Gv Dsp Lpr Firmware CRITICAL 9.8
CVE-2024-6047 KEVEPSS 10%

Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vu…

Mitigation only
Fix from $2,300 2024-06-17
Android HIGH 7.8
CVE-2024-32896 KEV

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution pr…

No fix yet
Fix from $1,950 2024-06-13
Commerce CRITICAL 9.8
CVE-2024-34102 KEVEPSS 100%

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XX…

Fix: 1.5.0+
Fix from $2,300 2024-06-13
Windows 10 1507 HIGH 7.8
CVE-2024-35250 KEVEPSS 25%

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

Fix: 10.0.10240.20680 / 10.0.14393.7070+
Fix from $1,950 2024-06-11
Windows 10 1507 HIGH 7.0
CVE-2024-30088 KEVEPSS 68%

Windows Kernel Elevation of Privilege Vulnerability

Fix: 10.0.10240.20680 / 10.0.14393.7070+
Fix from $1,950 2024-06-11
Debian Linux HIGH 7.8
CVE-2024-36971 KEV

In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce …

Fix: 4.19.316 / 5.4.278+
Fix from $1,950 2024-06-10
PHP CRITICAL 9.8
CVE-2024-4577 KEVEPSS 100%

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to us…

Fix: 8.1.29 / 8.2.20+
Fix from $2,300 2024-06-09
Bifrost Gpu Kernel Driver HIGH 7.8
CVE-2024-4610 KEV

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make impro…

Mitigation only
Fix from $1,950 2024-06-07
Debian Linux MEDIUM 6.1
CVE-2024-37383 KEVEPSS 73%

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

Fix: 1.5.7 / 1.6.7+
Fix from $1,600 2024-06-07
Serv U HIGH 7.5
CVE-2024-28995 KEVEPSS 100%

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

Fix: 15.4.2+
Fix from $1,950 2024-06-06
Endpoint Manager HIGH 8.8
CVE-2024-29824 KEVEPSS 100%

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network…

Fix: 2022+
Fix from $1,950 2024-05-31
Http File Server CRITICAL 9.8
CVE-2024-23692 KEVEPSS 99%

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, …

Fix: after 2.4
Fix from $2,300 2024-05-31
Report Server 2024 CRITICAL 9.8
CVE-2024-4358 KEVEPSS 97%

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Se…

Fix: after 10.0.24.305
Fix from $2,300 2024-05-29
Quantum Spark Firmware HIGH 8.6
CVE-2024-24919 KEVEPSS 100%

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote …

Patch available
Fix from $1,950 2024-05-28
Chrome CRITICAL 9.6
CVE-2024-5274 KEVEPSS 7%

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…

Fix: 125.0.6422.112+
Fix from $2,300 2024-05-28
Javs Viewer HIGH 8.4
CVE-2024-4978 KEVEPSS 27%

Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A re…

Mitigation only
Fix from $1,950 2024-05-23
Chrome CRITICAL 9.6
CVE-2024-4947 KEVEPSS 15%

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 125.0.6422.60+
Fix from $2,300 2024-05-15
Windows 10 1507 HIGH 7.8
CVE-2024-30051 KEVEPSS 6%

Windows DWM Core Library Elevation of Privilege Vulnerability

Fix: 10.0.10240.20651 / 10.0.14393.6981+
Fix from $1,950 2024-05-14