Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-5217 KEVEPSS 100% ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. Th… Servicenow Mitigation only Fix from $2,3002024-07-10 CRITICAL 9.8 CVE-2024-4879 KEVEPSS 100% ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerabili… Servicenow Mitigation only Fix from $2,3002024-07-10 HIGH 7.5 CVE-2024-38112 KEVEPSS 84% Windows MSHTML Platform Spoofing Vulnerability Windows 10 1507 10.0.10240.20710 / 10.0.14393.7159+ Fix from $1,9502024-07-09 HIGH 7.2 CVE-2024-38094 KEVEPSS 51% Microsoft SharePoint Remote Code Execution Vulnerability Sharepoint Server Patch available Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-38080 KEVEPSS 7% Windows Hyper-V Elevation of Privilege Vulnerability Windows 11 21h2 10.0.20348.2582 / 10.0.22000.3079+ Fix from $1,9502024-07-09 MEDIUM 5.3 CVE-2024-39891 KEV In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain … Authy 25.1.0 / 26.1.0+ Fix from $1,6002024-07-02 CRITICAL 9.1 CVE-2024-38475 KEVEPSS 100% Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are p… HTTP Server 2.4.60 / 10.2.1.14-75sv+ Fix from $2,3002024-07-01 MEDIUM 6.7 CVE-2024-20399 KEV A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary … Nx Os Mitigation only Fix from $1,6002024-07-01 CRITICAL 9.8 CVE-2024-36401 KEVEPSS 100% GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multipl… Geoserver 2.22.6 / 2.23.6+ Fix from $2,3002024-07-01 CRITICAL 9.8 CVE-2024-4885 KEVEPSS 99% In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.Exp… Whatsup Gold 23.1.3+ Fix from $2,3002024-06-25 HIGH 7.2 CVE-2024-37085 KEVEPSS 26% VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access… Cloud Foundation 5.2+ Fix from $1,9502024-06-25 CRITICAL 9.8 CVE-2024-37079 KEVEPSS 22% vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter … Cloud Foundation 5.2+ Fix from $2,3002024-06-18 CRITICAL 9.8 CVE-2024-6047 KEVEPSS 10% Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vu… Gv Dsp Lpr Firmware Mitigation only Fix from $2,3002024-06-17 HIGH 7.8 CVE-2024-32896 KEV there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution pr… Android No fix yet Fix from $1,9502024-06-13 CRITICAL 9.8 CVE-2024-34102 KEVEPSS 100% Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XX… Commerce 1.5.0+ Fix from $2,3002024-06-13 HIGH 7.8 CVE-2024-35250 KEVEPSS 25% Windows Kernel-Mode Driver Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20680 / 10.0.14393.7070+ Fix from $1,9502024-06-11 HIGH 7.0 CVE-2024-30088 KEVEPSS 68% Windows Kernel Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20680 / 10.0.14393.7070+ Fix from $1,9502024-06-11 HIGH 7.8 CVE-2024-36971 KEV In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce … Debian Linux 4.19.316 / 5.4.278+ Fix from $1,9502024-06-10 CRITICAL 9.8 CVE-2024-4577 KEVEPSS 100% In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to us… PHP 8.1.29 / 8.2.20+ Fix from $2,3002024-06-09 HIGH 7.8 CVE-2024-4610 KEV Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make impro… Bifrost Gpu Kernel Driver Mitigation only Fix from $1,9502024-06-07 MEDIUM 6.1 CVE-2024-37383 KEVEPSS 73% Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. Debian Linux 1.5.7 / 1.6.7+ Fix from $1,6002024-06-07 HIGH 7.5 CVE-2024-28995 KEVEPSS 100% SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine. Serv U 15.4.2+ Fix from $1,9502024-06-06 HIGH 8.8 CVE-2024-29824 KEVEPSS 100% An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network… Endpoint Manager 2022+ Fix from $1,9502024-05-31 CRITICAL 9.8 CVE-2024-23692 KEVEPSS 99% Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, … Http File Server after 2.4 Fix from $2,3002024-05-31 CRITICAL 9.8 CVE-2024-4358 KEVEPSS 97% In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Se… Report Server 2024 after 10.0.24.305 Fix from $2,3002024-05-29 HIGH 8.6 CVE-2024-24919 KEVEPSS 100% Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote … Quantum Spark Firmware Patch available Fix from $1,9502024-05-28 CRITICAL 9.6 CVE-2024-5274 KEVEPSS 7% Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML… Chrome 125.0.6422.112+ Fix from $2,3002024-05-28 HIGH 8.4 CVE-2024-4978 KEVEPSS 27% Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A re… Javs Viewer Mitigation only Fix from $1,9502024-05-23 CRITICAL 9.6 CVE-2024-4947 KEVEPSS 15% Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … Chrome 125.0.6422.60+ Fix from $2,3002024-05-15 HIGH 7.8 CVE-2024-30051 KEVEPSS 6% Windows DWM Core Library Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20651 / 10.0.14393.6981+ Fix from $1,9502024-05-14