Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 1507 HIGH 8.8
CVE-2024-30040 KEV

Windows MSHTML Platform Security Feature Bypass Vulnerability

Fix: 10.0.10240.20651 / 10.0.14393.6981+
Fix from $1,950 2024-05-14
Chrome HIGH 8.8
CVE-2024-4761 KEVEPSS 11%

Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted H…

Fix: 124.0.6367.207+
Fix from $1,950 2024-05-14
Chrome CRITICAL 9.6
CVE-2024-4671 KEVEPSS 8%

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially …

Fix: 124.0.6367.201+
Fix from $2,300 2024-05-14
Ofbiz CRITICAL 9.8
CVE-2024-32113 KEVEPSS 99%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before …

Fix: 18.12.13+
Fix from $2,300 2024-05-08
Tl Wr841n Firmware MEDIUM 6.5
CVE-2023-50224 KEVEPSS 17%

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to d…

Mitigation only
Fix from $1,600 2024-05-03
Adaptive Security Appliance Software MEDIUM 6.0
CVE-2024-20359 KEVEPSS 19%

A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Secu…

Mitigation only
Fix from $1,600 2024-04-24
Adaptive Security Appliance Software HIGH 8.6
CVE-2024-20353 KEVEPSS 71%

A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) S…

Mitigation only
Fix from $1,950 2024-04-24
Crushftp CRITICAL 10.0
CVE-2024-4040 KEVEPSS 100%

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote at…

Fix: 10.7.1 / 11.1.0+
Fix from $2,300 2024-04-22
Hugegraph CRITICAL 9.8
CVE-2024-27348 KEVEPSS 99%

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & …

Fix: 1.3.0+
Fix from $2,300 2024-04-22
Pan Os CRITICAL 10.0
CVE-2024-3400 KEVEPSS 100%

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for speci…

Mitigation only
Fix from $2,300 2024-04-12
Windows 10 1809 HIGH 8.8
CVE-2024-29988 KEVEPSS 45%

SmartScreen Prompt Security Feature Bypass Vulnerability

Fix: 10.0.17763.5696 / 10.0.19044.4291+
Fix from $1,950 2024-04-09
Android HIGH 7.8
CVE-2024-29748 KEV

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution pr…

Fix: 2024-04-05+
Fix from $1,950 2024-04-05
Android MEDIUM 5.5
CVE-2024-29745 KEV

there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution pr…

Mitigation only
Fix from $1,600 2024-04-05
Dns 320l Firmware CRITICAL 9.8
CVE-2024-3273 KEVEPSS 100%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to…

Mitigation only
Fix from $2,300 2024-04-04
Dns 320l Firmware CRITICAL 9.8
CVE-2024-3272 KEVEPSS 98%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-…

Mitigation only
Fix from $2,300 2024-04-04
.net Framework HIGH 7.5
CVE-2024-29059 KEVEPSS 99%

.NET Framework Information Disclosure Vulnerability

Mitigation only
Fix from $1,950 2024-03-23
Coldfusion HIGH 7.4
CVE-2024-20767 KEVEPSS 99%

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system r…

Mitigation only
Fix from $1,950 2024-03-18
Windows 10 1507 HIGH 7.8
CVE-2024-26169 KEV

Windows Error Reporting Service Elevation of Privilege Vulnerability

Fix: 10.0.10240.20526 / 10.0.14393.6796+
Fix from $1,950 2024-03-12
Forticlient Enterprise Management Server CRITICAL 9.8
CVE-2023-48788 KEVEPSS 98%

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiC…

Fix: 7.0.11 / 7.2.3+
Fix from $2,300 2024-03-12
Ipados HIGH 7.8
CVE-2024-23296 KEV

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macO…

Fix: 1.1 / 10.4+
Fix from $1,950 2024-03-05
Ipados HIGH 7.8
CVE-2024-23225 KEV

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macO…

Fix: 1.1 / 10.4+
Fix from $1,950 2024-03-05
Teamcity HIGH 7.3
CVE-2024-27199 KEVEPSS 100%

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

Fix: 2023.11.4+
Fix from $1,950 2024-03-04
Teamcity CRITICAL 9.8
CVE-2024-27198 KEVEPSS 100%

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

Fix: 2023.11.4+
Fix from $2,300 2024-03-04
Loadmaster CRITICAL 9.8
CVE-2024-1212 KEVEPSS 95%

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

Fix: 7.2.48.10 / 7.2.54.8+
Fix from $2,300 2024-02-21
Screenconnect CRITICAL 10.0
CVE-2024-1709 KEVEPSS 100%

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may all…

Fix: 23.9.8+
Fix from $2,300 2024-02-21
Screenconnect HIGH 8.4
CVE-2024-1708 KEVEPSS 88%

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote …

Fix: 23.9.8+
Fix from $1,950 2024-02-21
Agile Product Lifecycle Management HIGH 8.8
CVE-2024-20953 KEV

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily e…

Mitigation only
Fix from $1,950 2024-02-17
Fortiproxy CRITICAL 9.8
CVE-2024-23113 KEVEPSS 62%

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy …

Fix: after 7.4.2
Fix from $2,300 2024-02-15
365 Apps CRITICAL 9.8
CVE-2024-21413 KEVEPSS 95%

Microsoft Outlook Remote Code Execution Vulnerability

Patch available
Fix from $2,300 2024-02-13
Windows 10 1809 HIGH 8.1
CVE-2024-21412 KEVEPSS 95%

Internet Shortcut Files Security Feature Bypass Vulnerability

Fix: 10.0.17763.5458 / 10.0.19044.4046+
Fix from $1,950 2024-02-13