Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.3
CVE-2024-38226 KEV
Microsoft Publisher Security Feature Bypass Vulnerability
Office 2019
Patch available
MEDIUM 5.4
CVE-2024-38217 KEVEPSS 10%
Windows Mark of the Web Security Feature Bypass Vulnerability
Windows 10 1507
10.0.10240.20766 / 10.0.14393.7336+
HIGH 7.8
CVE-2024-38014 KEVEPSS 6%
Windows Installer Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20766 / 10.0.14393.7336+
CRITICAL 9.8
CVE-2024-40711 KEVEPSS 90%
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
Veeam Backup \& Replication
12.2.0.334+
CRITICAL 9.8
CVE-2024-20439 KEVEPSS 92%
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a sta…
Smart License Utility
2.3.0+
HIGH 7.5
CVE-2024-45195 KEVEPSS 100%
Direct Request ('Forced Browsing') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.16.
Users are recommended to upgrad…
Ofbiz
18.12.16+
CRITICAL 9.8
CVE-2024-6670 KEVEPSS 95%
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted p…
Whatsup Gold
24.0+
CRITICAL 9.8
CVE-2024-40766 KEVEPSS 18%
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource…
Sonicos
5.9.2.14-13o / 6.5.2.8-2n+
HIGH 7.2
CVE-2024-39717 KEV
The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with …
Versa Director
Mitigation only
CRITICAL 9.1
CVE-2024-28987 KEVEPSS 93%
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access inter…
Web Help Desk
12.8.3+
CRITICAL 9.6
CVE-2024-7971 KEVEPSS 21%
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium …
Chrome
128.0.2739.42 / 128.0.6613.84+
HIGH 8.8
CVE-2024-7965 KEVEPSS 19%
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a cra…
Chrome
128.0.2739.42 / 128.0.6613.84+
HIGH 7.8
CVE-2024-7262 KEV
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows al…
Wps Office
12.2.0.16412+
CRITICAL 9.8
CVE-2024-28986 KEVEPSS 85%
SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an…
Web Help Desk
after 12.8.2
CRITICAL 9.8
CVE-2024-7593 KEVEPSS 100%
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker t…
Virtual Traffic Manager
Patch available
MEDIUM 6.5
CVE-2024-38213 KEVEPSS 14%
Windows Mark of the Web Security Feature Bypass Vulnerability
Windows 10 1507
10.0.10240.20680 / 10.0.14393.7070+
HIGH 7.8
CVE-2024-38193 KEVEPSS 27%
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20751 / 10.0.14393.7259+
HIGH 8.8
CVE-2024-38189 KEVEPSS 8%
Microsoft Project Remote Code Execution Vulnerability
365 Apps
16.0.5461.1001+
HIGH 7.5
CVE-2024-38178 KEVEPSS 41%
Scripting Engine Memory Corruption Vulnerability
Windows 10 1507
10.0.10240.20751 / 10.0.14393.7259+
HIGH 7.8
CVE-2024-38107 KEV
Windows Power Dependency Coordinator Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20751 / 10.0.14393.7259+
HIGH 7.0
CVE-2024-38106 KEVEPSS 6%
Windows Kernel Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20751 / 10.0.14393.7259+
HIGH 7.2
CVE-2024-41710 KEVEPSS 42%
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.13…
6970 Firmware
after 6.4.0.136
MEDIUM 6.1
CVE-2024-27443 KEVEPSS 24%
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature o…
Collaboration
10.0.7+
HIGH 7.2
CVE-2024-7694 KEV
ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on …
Threatsonar Anti Ransomware
3.5.0+
CRITICAL 9.8
CVE-2024-7399 KEVEPSS 92%
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to wr…
Magicinfo 9 Server
21.1050.0+
CRITICAL 9.3
CVE-2024-42009 KEVEPSS 80%
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim…
Webmail
1.5.8 / 1.6.8+
CRITICAL 9.8
CVE-2024-38856 KEVEPSS 99%
Incorrect Authorization vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: through 18.12.14.
Users are recommended to upgrade to versi…
Ofbiz
18.12.15+
CRITICAL 9.8
CVE-2023-45249 KEVEPSS 53%
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-…
Cyber Infrastructure
5.0.1-61 / 5.1.1-71+
HIGH 7.5
CVE-2024-21182 KEVEPSS 50%
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…
Weblogic Server
Mitigation only
CRITICAL 9.8
CVE-2024-5910 KEVEPSS 92%
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with n…
Expedition
1.2.92+