Known Exploited

    Dashboard / Known Exploited

    Filters
    7.5
    High

    CVE-2024-29059

    Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.

    Alert Date:4 Feb 2025
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29059 ; https://nvd.nist.gov/vuln/detail/CVE-2024-29059

    9.8
    Critical

    CVE-2024-45195

    Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.

    Alert Date:4 Feb 2025
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://ofbiz.apache.org/security.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-45195

    10
    Critical

    CVE-2025-24085

    Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges.

    Alert Date:29 Jan 2025
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://support.apple.com/en-us/122066 ; https://support.apple.com/en-us/122068 ; https://support.apple.com/en-us/122071 ; https://support.apple.com/en-us/122072 ; https://support.apple.com/en-us/122073 ; https://nvd.nist.gov/vuln/detail/CVE-2025-24085

    9.8
    Critical

    CVE-2025-23006

    SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.

    Alert Date:24 Jan 2025
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0002 ; https://nvd.nist.gov/vuln/detail/CVE-2025-23006

    6.9
    Medium

    CVE-2020-11023

    JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of the user's browser.

    Alert Date:23 Jan 2025
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/jquery/jquery/security/advisories/GHSA-jpcq-cgw6-v4j6 ; https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ ; https://nvd.nist.gov/vuln/detail/CVE-2020-11023

    10
    Critical

    CVE-2024-50603

    Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.

    Alert Date:16 Jan 2025
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://docs.aviatrix.com/documentation/latest/release-notices/psirt-advisories/psirt-advisories.html?expand=true ; https://nvd.nist.gov/vuln/detail/CVE-2024-50603

    7.8
    High

    CVE-2025-21335

    Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.

    Alert Date:14 Jan 2025
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-21335 ; https://nvd.nist.gov/vuln/detail/CVE-2025-21335

    7.8
    High

    CVE-2025-21334

    Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.

    Alert Date:14 Jan 2025
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-21334 ; https://nvd.nist.gov/vuln/detail/CVE-2025-21334

    7.8
    High

    CVE-2025-21333

    Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.

    Alert Date:14 Jan 2025
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-21333 ; https://nvd.nist.gov/vuln/detail/CVE-2025-21333

    9.6
    Critical

    CVE-2024-55591

    Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

    Alert Date:14 Jan 2025
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://fortiguard.fortinet.com/psirt/FG-IR-24-535 ; https://nvd.nist.gov/vuln/detail/CVE-2024-55591

    9.6
    Critical

    CVE-2023-48365

    Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.

    Alert Date:13 Jan 2025
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/tac-p/2120510 ; https://nvd.nist.gov/vuln/detail/CVE-2023-48365

    6.6
    Medium

    CVE-2024-12686

    BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user.

    Alert Date:13 Jan 2025
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://www.beyondtrust.com/trust-center/security-advisories/bt24-11 ; https://nvd.nist.gov/vuln/detail/CVE-2024-12686

    9
    Critical

    CVE-2025-0282

    Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.

    Alert Date:8 Jan 2025
    Action:Apply mitigations as set forth in the CISA instructions linked below to include conducting hunt activities, taking remediation actions if applicable, and applying updates prior to returning a device to service.

    Note: CISA Mitigation Instructions: https://www.cisa.gov/cisa-mitigation-instructions-CVE-2025-0282 Additional References: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283 ; https://nvd.nist.gov/vuln/detail/CVE-2025-0282

    9.8
    Critical

    CVE-2020-2883

    Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3.

    Alert Date:7 Jan 2025
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://www.oracle.com/security-alerts/cpuapr2020.html ; https://nvd.nist.gov/vuln/detail/CVE-2020-2883

    4.4
    Medium

    CVE-2024-55550

    Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.

    Alert Date:7 Jan 2025
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029 ; https://nvd.nist.gov/vuln/detail/CVE-2024-55550

    9.1
    Critical

    CVE-2024-41713

    Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server.

    Alert Date:7 Jan 2025
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029 ; https://nvd.nist.gov/vuln/detail/CVE-2024-41713

    7.5
    High

    CVE-2024-3393

    Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

    Alert Date:30 Dec 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://security.paloaltonetworks.com/CVE-2024-3393 ; https://nvd.nist.gov/vuln/detail/CVE-2024-3393

    8.1
    High

    CVE-2021-44207

    Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be obtained via a separate vulnerability or other channel.

    Alert Date:23 Dec 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please contact the product developer for support and vulnerability mitigation.

    Note: https://www.acclaimsystems.com/#contact ; https://www.tnatc.org/#contact ; https://nvd.nist.gov/vuln/detail/CVE-2021-44207

    9.8
    Critical

    CVE-2024-12356

    BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user.

    Alert Date:19 Dec 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://www.beyondtrust.com/trust-center/security-advisories/bt24-10 ; https://nvd.nist.gov/vuln/detail/CVE-2024-12356

    7.2
    High

    CVE-2021-40407

    Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.

    Alert Date:18 Dec 2024
    Action:The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

    Note: https://reolink.com/product-eol/ ; https://reolink.com/download-center/ ; https://nvd.nist.gov/vuln/detail/CVE-2021-40407

    7.2
    High

    CVE-2019-11001

    Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root.

    Alert Date:18 Dec 2024
    Action:The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

    Note: https://reolink.com/product-eol/ ; https://reolink.com/download-center/ ; https://nvd.nist.gov/vuln/detail/CVE-2019-11001

    9.8
    Critical

    CVE-2022-23227

    NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.

    Alert Date:18 Dec 2024
    Action:The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

    Note: https://nuuo.com/wp-content/uploads/2023/03/NUUO-EOL-letter_NVRmini-2-and-NVRsolo-series.pdf ; https://nvd.nist.gov/vuln/detail/CVE-2022-23227

    9.8
    Critical

    CVE-2018-14933

    NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.

    Alert Date:18 Dec 2024
    Action:The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

    Note: https://nuuo.com/wp-content/uploads/2023/03/NUUO-EOL-letter%EF%BC%BFNVRmini-2-and-NVRsolo-series.pdf ; https://nvd.nist.gov/vuln/detail/CVE-2018-14933

    9.8
    Critical

    CVE-2024-55956

    Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

    Alert Date:17 Dec 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Update-CVE-2024-55956 ; https://nvd.nist.gov/vuln/detail/CVE-2024-55956

    7.8
    High

    CVE-2024-35250

    Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges.

    Alert Date:16 Dec 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35250 ; https://nvd.nist.gov/vuln/detail/CVE-2024-35250

    7.4
    High

    CVE-2024-20767

    Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.

    Alert Date:16 Dec 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://helpx.adobe.com/security/products/coldfusion/apsb24-14.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-20767

    9.8
    Critical

    CVE-2024-50623

    Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.

    Alert Date:13 Dec 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Update ; https://nvd.nist.gov/vuln/detail/CVE-2024-50623

    7.8
    High

    CVE-2024-49138

    Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges.

    Alert Date:10 Dec 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49138 ; https://nvd.nist.gov/vuln/detail/CVE-2024-49138

    10
    Critical

    CVE-2024-51378

    CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property.

    Alert Date:4 Dec 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://cyberpanel.net/KnowledgeBase/home/change-logs/ ; https://nvd.nist.gov/vuln/detail/CVE-2024-51378

    7.5
    High

    CVE-2024-11667

    Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.

    Alert Date:3 Dec 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-protecting-against-recent-firewall-threats-11-21-2024 ; https://nvd.nist.gov/vuln/detail/CVE-2024-11667

    9.8
    Critical

    CVE-2024-11680

    ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

    Alert Date:3 Dec 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744 ; https://nvd.nist.gov/vuln/detail/CVE-2024-11680

    7.5
    High

    CVE-2023-45727

    North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated attacker to conduct an XXE attack.

    Alert Date:3 Dec 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://www.proself.jp/information/153/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-45727

    9.8
    Critical

    CVE-2023-28461

    Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.

    Alert Date:25 Nov 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf ; https://nvd.nist.gov/vuln/detail/CVE-2023-28461

    7.5
    High

    CVE-2024-21287

    Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this vulnerability may result in unauthenticated file disclosure.

    Alert Date:21 Nov 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://www.oracle.com/security-alerts/alert-cve-2024-21287.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-21287

    6.3
    Medium

    CVE-2024-44309

    Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to a cross-site scripting (XSS) attack.

    Alert Date:21 Nov 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://support.apple.com/en-us/121752, https://support.apple.com/en-us/121753, https://support.apple.com/en-us/121754, https://support.apple.com/en-us/121755, https://support.apple.com/en-us/121756 ; https://nvd.nist.gov/vuln/detail/CVE-2024-44309

    8.8
    High

    CVE-2024-44308

    Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to arbitrary code execution.

    Alert Date:21 Nov 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://support.apple.com/en-us/121752, https://support.apple.com/en-us/121753, https://support.apple.com/en-us/121754, https://support.apple.com/en-us/121755, https://support.apple.com/en-us/121756 ; https://nvd.nist.gov/vuln/detail/CVE-2024-44308

    7.5
    High

    CVE-2024-38813

    VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet.

    Alert Date:20 Nov 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968 ; https://nvd.nist.gov/vuln/detail/CVE-2024-38813

    9.8
    Critical

    CVE-2024-38812

    VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.

    Alert Date:20 Nov 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968 ; https://nvd.nist.gov/vuln/detail/CVE-2024-38812

    7.2
    High

    CVE-2024-9474

    Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.

    Alert Date:18 Nov 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, the management interfaces for affected devices should not be exposed to untrusted networks, including the internet.

    Note: https://security.paloaltonetworks.com/CVE-2024-9474 ; https://nvd.nist.gov/vuln/detail/CVE-2024-9474

    9.8
    Critical

    CVE-2024-0012

    Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.

    Alert Date:18 Nov 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, management interface for affected devices should not be exposed to untrusted networks, including the internet.

    Note: https://security.paloaltonetworks.com/CVE-2024-0012 ; https://nvd.nist.gov/vuln/detail/CVE-2024-0012

    10
    Critical

    CVE-2024-1212

    Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution.

    Alert Date:18 Nov 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://community.progress.com/s/article/Release-Notice-LMOS-7-2-59-2-7-2-54-8-7-2-48-10-CVE-2024-1212 ; https://nvd.nist.gov/vuln/detail/CVE-2024-1212

    9.1
    Critical

    CVE-2024-9465

    Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.

    Alert Date:14 Nov 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://security.paloaltonetworks.com/PAN-SA-2024-0010 ; https://nvd.nist.gov/vuln/detail/CVE-2024-9465

    7.5
    High

    CVE-2024-9463

    Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

    Alert Date:14 Nov 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://security.paloaltonetworks.com/PAN-SA-2024-0010 ; https://nvd.nist.gov/vuln/detail/CVE-2024-9463

    5.3
    Medium

    CVE-2021-26086

    Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.

    Alert Date:12 Nov 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://jira.atlassian.com/browse/JRASERVER-72695 ; https://nvd.nist.gov/vuln/detail/CVE-2021-26086

    5.4
    Medium

    CVE-2014-2120

    Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.

    Alert Date:12 Nov 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-CVE-2014-2120 ; https://nvd.nist.gov/vuln/detail/CVE-2014-2120

    10
    Critical

    CVE-2021-41277

    Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data.

    Alert Date:12 Nov 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://github.com/metabase/metabase/security/advisories/GHSA-w73v-6p7p-fpfr ; https://nvd.nist.gov/vuln/detail/CVE-2021-41277

    6.5
    Medium

    CVE-2024-43451

    Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user.

    Alert Date:12 Nov 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43451 ; https://nvd.nist.gov/vuln/detail/CVE-2024-43451

    8.8
    High

    CVE-2024-49039

    Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions.

    Alert Date:12 Nov 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49039 ; https://nvd.nist.gov/vuln/detail/CVE-2024-49039

    9.8
    Critical

    CVE-2019-16278

    Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution.

    Alert Date:7 Nov 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://www.nazgul.ch/dev/nostromo_cl.txt ; https://nvd.nist.gov/vuln/detail/CVE-2019-16278

    10
    Critical

    CVE-2024-51567

    CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root.

    Alert Date:7 Nov 2024
    Action:Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Note: https://cyberpanel.net/blog/detials-and-fix-of-recent-security-issue-and-patch-of-cyberpanel ; https://nvd.nist.gov/vuln/detail/CVE-2024-51567

    Items Per Page