Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2024-11120 KEVEPSS 29%
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject a…
Gv Vs12 Firmware
Mitigation only
HIGH 7.3
CVE-2024-43093 KEV
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive direc…
Android
Patch available
HIGH 8.0
CVE-2024-8069 KEVEPSS 15%
Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user …
Session Recording
2407+
HIGH 8.0
CVE-2024-8068 KEV
Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Activ…
Session Recording
2407+
HIGH 8.8
CVE-2024-49039 KEVEPSS 14%
Windows Task Scheduler Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20826 / 10.0.14393.7515+
MEDIUM 6.5
CVE-2024-43451 KEVEPSS 82%
NTLM Hash Disclosure Spoofing Vulnerability
Windows 10 1507
10.0.10240.20826 / 10.0.14393.7515+
CRITICAL 9.8
CVE-2024-51567 KEVEPSS 87%
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute …
Cyberpanel
2.3.8+
CRITICAL 9.8
CVE-2024-51378 KEVEPSS 95%
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and e…
Cyberpanel
2.3.8+
CRITICAL 9.8
CVE-2024-50623 KEVEPSS 99%
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could …
Harmony
5.8.0.21+
MEDIUM 5.8
CVE-2024-20481 KEVEPSS 16%
A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)…
Secure Firewall Threat Defense
Mitigation only
CRITICAL 9.8
CVE-2024-47575 KEVEPSS 95%
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManage…
Fortimanager
6.2.13 / 6.4.15+
CRITICAL 9.1
CVE-2024-41713 KEVEPSS 98%
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated att…
Micollab
after 9.8.1.201
CRITICAL 9.8
CVE-2024-9537 KEV
ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vul…
Sl1
12.1.3 / 12.2.3+
CRITICAL 9.1
CVE-2024-9465 KEVEPSS 100%
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as pa…
Expedition
1.2.96+
HIGH 7.5
CVE-2024-9463 KEVEPSS 98%
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Exp…
Expedition
1.2.96+
CRITICAL 9.8
CVE-2024-9680 KEVEPSS 23%
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of t…
Firefox
115.16.0 / 115.16.1+
HIGH 8.1
CVE-2024-43573 KEVEPSS 44%
Windows MSHTML Platform Spoofing Vulnerability
Windows 10 1507
10.0.10240.20796 / 10.0.14393.7428+
HIGH 7.8
CVE-2024-43572 KEVEPSS 67%
Microsoft Management Console Remote Code Execution Vulnerability
Windows 10 1507
10.0.10240.20796 / 10.0.14393.7428+
CRITICAL 9.8
CVE-2024-43468 KEVEPSS 61%
Microsoft Configuration Manager Remote Code Execution Vulnerability
Configuration Manager 2403
No fix yet
HIGH 7.2
CVE-2024-9380 KEVEPSS 63%
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin p…
Endpoint Manager Cloud Services Appliance
5.0.2+
HIGH 7.2
CVE-2024-9379 KEVEPSS 43%
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitra…
Endpoint Manager Cloud Services Appliance
5.0.2+
HIGH 7.8
CVE-2024-43047 KEV
Memory corruption while maintaining memory maps of HLOS memory.
Fastconnect 6700 Firmware
Patch available
CRITICAL 9.8
CVE-2024-45519 KEVEPSS 100%
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 somet…
Zimbra Collaboration Suite
8.8.15 / 10.0.9+
CRITICAL 9.1
CVE-2024-8963 KEVEPSS 99%
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
Endpoint Manager Cloud Services Appliance
Mitigation only
HIGH 7.2
CVE-2024-8957 KEVEPSS 82%
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_a…
Pt30x Sdi Firmware
6.3.40+
CRITICAL 9.1
CVE-2024-8956 KEVEPSS 61%
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authent…
Pt30x Sdi Firmware
6.3.40+
CRITICAL 9.8
CVE-2024-38813 KEVEPSS 17%
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerabil…
Cloud Foundation
5.2+
CRITICAL 9.8
CVE-2024-38812 KEVEPSS 55%
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCen…
Cloud Foundation
5.2+
HIGH 7.2
CVE-2024-8190 KEVEPSS 89%
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to …
Cloud Services Appliance
Mitigation only
HIGH 8.8
CVE-2024-43461 KEVEPSS 52%
Windows MSHTML Platform Spoofing Vulnerability
Windows 10 1507
10.0.10240.20766 / 10.0.14393.7336+