Exploited vulnerabilities
CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.
| Score | CVE | Affected | EPSS | Published |
|---|---|---|---|---|
| 7.2 high | CVE-2024-8957 KEV | PTZOptics PT30X-SDI PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may lead to arbitrary command execution when ntp_client is started. When chained with CVE-2024-8956, a remote and unauthenticated attacker can execute arbitrary OS commands on affected devices. | 80% | 17 Sept 2024 |
| 9.1 critical | CVE-2024-8956 KEV | PTZOptics PT30X-SDI PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file. | 59% | 17 Sept 2024 |
| 9.8 critical | CVE-2024-38813 KEV | VMware vCenter Server The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet. | 17% | 17 Sept 2024 |
| 9.8 critical | CVE-2024-38812 KEV | VMware vCenter Server The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution. | 55% | 17 Sept 2024 |
| 7.2 high | CVE-2024-8190 KEV | Ivanti CSA (Cloud Services Appliance) An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability. | 89% | 10 Sept 2024 |
| 8.8 high | CVE-2024-43461 KEV | Microsoft Windows 10 Version 1507 Windows MSHTML Platform Spoofing Vulnerability | 54% | 10 Sept 2024 |
| 7.3 high | CVE-2024-38226 KEV | Microsoft Office 2019 Microsoft Publisher Security Feature Bypass Vulnerability | 2.7% | 10 Sept 2024 |
| 5.4 medium | CVE-2024-38217 KEV | Microsoft Windows 10 Version 1507 Windows Mark of the Web Security Feature Bypass Vulnerability | 10% | 10 Sept 2024 |
| 7.8 high | CVE-2024-38014 KEV | Microsoft Windows 10 Version 1507 Windows Installer Elevation of Privilege Vulnerability | 6.3% | 10 Sept 2024 |
| 9.8 critical | CVE-2024-40711 KEV | Veeam Backup and Recovery A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). | 90% | 7 Sept 2024 |
| 9.8 critical | CVE-2024-20439 KEV | Cisco Smart License Utility A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this vulnerability by using the static credentials to login to the affected system. A successful exploit could allow the attacker to login to the affected system with administrative rights over the CSLU application API. | 97% | 4 Sept 2024 |
| 7.5 high | CVE-2024-45195 KEV | Apache Software Foundation Apache OFBiz Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue. | >99% | 4 Sept 2024 |
| 9.8 critical | CVE-2024-6670 KEV | Progress Software Corporation WhatsUp Gold In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password. | 93% | 29 Aug 2024 |
| 9.8 critical | CVE-2024-40766 KEV | SonicWall SonicOS An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions. | 18% | 23 Aug 2024 |
| 7.2 high | CVE-2024-39717 KEV | Versa Director The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in. | 4.0% | 22 Aug 2024 |
| 9.1 critical | CVE-2024-28987 KEV | SolarWinds Web Help Desk The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data. | 93% | 21 Aug 2024 |
| 9.6 critical | CVE-2024-7971 KEV | Google Chrome Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 21% | 21 Aug 2024 |
| 8.8 high | CVE-2024-7965 KEV | Google Chrome Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 19% | 21 Aug 2024 |
| 9.3 critical | CVE-2024-7262 KEV | Kingsoft WPS Office Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document | 2.9% | 15 Aug 2024 |
| 9.8 critical | CVE-2024-28986 KEV | SolarWinds Web Help Desk SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing. However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available. | 85% | 13 Aug 2024 |