Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2024-30040 KEV Windows MSHTML Platform Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.20651 / 10.0.14393.6981+ Fix from $1,9502024-05-14 HIGH 8.8 CVE-2024-4761 KEVEPSS 11% Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted H… Chrome 124.0.6367.207+ Fix from $1,9502024-05-14 CRITICAL 9.6 CVE-2024-4671 KEVEPSS 8% Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially … Chrome 124.0.6367.201+ Fix from $2,3002024-05-14 CRITICAL 9.8 CVE-2024-32113 KEVEPSS 99% Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before … Ofbiz 18.12.13+ Fix from $2,3002024-05-08 MEDIUM 6.5 CVE-2023-50224 KEVEPSS 17% TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to d… Tl Wr841n Firmware Mitigation only Fix from $1,6002024-05-03 MEDIUM 6.0 CVE-2024-20359 KEVEPSS 19% A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Secu… Adaptive Security Appliance Software Mitigation only Fix from $1,6002024-04-24 HIGH 8.6 CVE-2024-20353 KEVEPSS 71% A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) S… Adaptive Security Appliance Software Mitigation only Fix from $1,9502024-04-24 CRITICAL 10.0 CVE-2024-4040 KEVEPSS 100% A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote at… Crushftp 10.7.1 / 11.1.0+ Fix from $2,3002024-04-22 CRITICAL 9.8 CVE-2024-27348 KEVEPSS 99% RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & … Hugegraph 1.3.0+ Fix from $2,3002024-04-22 CRITICAL 10.0 CVE-2024-3400 KEVEPSS 100% A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for speci… Pan Os Mitigation only Fix from $2,3002024-04-12 HIGH 8.8 CVE-2024-29988 KEVEPSS 45% SmartScreen Prompt Security Feature Bypass Vulnerability Windows 10 1809 10.0.17763.5696 / 10.0.19044.4291+ Fix from $1,9502024-04-09 HIGH 7.8 CVE-2024-29748 KEV there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution pr… Android 2024-04-05+ Fix from $1,9502024-04-05 MEDIUM 5.5 CVE-2024-29745 KEV there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution pr… Android Mitigation only Fix from $1,6002024-04-05 CRITICAL 9.8 CVE-2024-3273 KEVEPSS 100% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to… Dns 320l Firmware Mitigation only Fix from $2,3002024-04-04 CRITICAL 9.8 CVE-2024-3272 KEVEPSS 98% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-… Dns 320l Firmware Mitigation only Fix from $2,3002024-04-04 HIGH 7.5 CVE-2024-29059 KEVEPSS 99% .NET Framework Information Disclosure Vulnerability .net Framework Mitigation only Fix from $1,9502024-03-23 HIGH 7.4 CVE-2024-20767 KEVEPSS 99% ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system r… Coldfusion Mitigation only Fix from $1,9502024-03-18 HIGH 7.8 CVE-2024-26169 KEV Windows Error Reporting Service Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20526 / 10.0.14393.6796+ Fix from $1,9502024-03-12 CRITICAL 9.8 CVE-2023-48788 KEVEPSS 98% A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiC… Forticlient Enterprise Management Server 7.0.11 / 7.2.3+ Fix from $2,3002024-03-12 HIGH 7.8 CVE-2024-23296 KEV A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macO… Ipados 1.1 / 10.4+ Fix from $1,9502024-03-05 HIGH 7.8 CVE-2024-23225 KEV A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macO… Ipados 1.1 / 10.4+ Fix from $1,9502024-03-05 HIGH 7.3 CVE-2024-27199 KEVEPSS 100% In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible Teamcity 2023.11.4+ Fix from $1,9502024-03-04 CRITICAL 9.8 CVE-2024-27198 KEVEPSS 100% In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible Teamcity 2023.11.4+ Fix from $2,3002024-03-04 CRITICAL 9.8 CVE-2024-1212 KEVEPSS 95% Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution. Loadmaster 7.2.48.10 / 7.2.54.8+ Fix from $2,3002024-02-21 CRITICAL 10.0 CVE-2024-1709 KEVEPSS 100% ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may all… Screenconnect 23.9.8+ Fix from $2,3002024-02-21 HIGH 8.4 CVE-2024-1708 KEVEPSS 88% ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote … Screenconnect 23.9.8+ Fix from $1,9502024-02-21 HIGH 8.8 CVE-2024-20953 KEV Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily e… Agile Product Lifecycle Management Mitigation only Fix from $1,9502024-02-17 CRITICAL 9.8 CVE-2024-23113 KEVEPSS 62% A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy … Fortiproxy after 7.4.2 Fix from $2,3002024-02-15 CRITICAL 9.8 CVE-2024-21413 KEVEPSS 95% Microsoft Outlook Remote Code Execution Vulnerability 365 Apps Patch available Fix from $2,3002024-02-13 HIGH 8.1 CVE-2024-21412 KEVEPSS 95% Internet Shortcut Files Security Feature Bypass Vulnerability Windows 10 1809 10.0.17763.5458 / 10.0.19044.4046+ Fix from $1,9502024-02-13