Exploited vulnerabilities
CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.
| Score | CVE | Affected | EPSS | Published |
|---|---|---|---|---|
| 8.8 high | CVE-2024-49039 KEV | Microsoft Windows Server 2025 Windows Task Scheduler Elevation of Privilege Vulnerability | 14% | 12 Nov 2024 |
| 6.5 medium | CVE-2024-43451 KEV | Microsoft Windows Server 2025 NTLM Hash Disclosure Spoofing Vulnerability | 84% | 12 Nov 2024 |
| 9.8 critical | CVE-2024-51567 KEV | cyberpanel upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected. | 87% | 29 Oct 2024 |
| 9.8 critical | CVE-2024-51378 KEV | cyberpanel getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected. | 95% | 29 Oct 2024 |
| 9.8 critical | CVE-2024-50623 KEV | cleo harmomy In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution. | 99% | 28 Oct 2024 |
| 5.8 medium | CVE-2024-20481 KEV | Cisco Adaptive Security Appliance (ASA) Software A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion. An attacker could exploit this vulnerability by sending a large number of VPN authentication requests to an affected device. A successful exploit could allow the attacker to exhaust resources, resulting in a DoS of the RAVPN service on the affected device. Depending on the impact of the attack, a reload of the device may be required to restore the RAVPN service. Services that are not related to VPN are not affected. Cisco Talos discussed these attacks in the blog post Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials. | 16% | 23 Oct 2024 |
| 9.8 critical | CVE-2024-47575 KEV | Fortinet FortiManager A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests. | 95% | 23 Oct 2024 |
| 9.1 critical | CVE-2024-41713 KEV | mitel micollab A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations. | 98% | 21 Oct 2024 |
| 9.3 critical | CVE-2024-9537 KEV | ScienceLogic SL1 ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made available for all SL1 versions back to version lines 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x. | 3.8% | 18 Oct 2024 |
| 9.2 critical | CVE-2024-9465 KEV | Palo Alto Networks Expedition An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system. | >99% | 9 Oct 2024 |
| 9.9 critical | CVE-2024-9463 KEV | Palo Alto Networks Expedition An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls. | 99% | 9 Oct 2024 |
| 9.8 critical | CVE-2024-9680 KEV | Mozilla Firefox An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0. | 23% | 9 Oct 2024 |
| 8.1 high | CVE-2024-43573 KEV | Microsoft Windows 10 Version 1507 Windows MSHTML Platform Spoofing Vulnerability | 46% | 8 Oct 2024 |
| 7.8 high | CVE-2024-43572 KEV | Microsoft Windows 10 Version 1507 Microsoft Management Console Remote Code Execution Vulnerability | 67% | 8 Oct 2024 |
| 9.8 critical | CVE-2024-43468 KEV | Microsoft Configuration Manager Microsoft Configuration Manager Remote Code Execution Vulnerability | 81% | 8 Oct 2024 |
| 7.2 high | CVE-2024-9380 KEV | Ivanti CSA (Cloud Services Appliance) An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution. | 60% | 8 Oct 2024 |
| 7.2 high | CVE-2024-9379 KEV | Ivanti CSA (Cloud Services Appliance) SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements. | 44% | 8 Oct 2024 |
| 7.8 high | CVE-2024-43047 KEV | Qualcomm, Inc. Snapdragon Memory corruption while maintaining memory maps of HLOS memory. | 0.67% | 7 Oct 2024 |
| 9.8 critical | CVE-2024-45519 KEV | synacor zimbra collaboration suite The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands. | >99% | 2 Oct 2024 |
| 9.1 critical | CVE-2024-8963 KEV | Ivanti CSA (Cloud Services Appliance) Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality. | 99% | 19 Sept 2024 |