Exploited vulnerabilities

CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.

46,824 CVEs · 1,734 known exploited · CVE data updated 2 hours ago · EPSS 6 hours ago

1,734 results · page 23 of 87 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Published
9.8 critical CVE-2024-7593 KEV Ivanti vTM Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel. >99% 13 Aug 2024
6.5 medium CVE-2024-38213 KEV Microsoft Windows 10 Version 1809 Windows Mark of the Web Security Feature Bypass Vulnerability 14% 13 Aug 2024
7.8 high CVE-2024-38193 KEV Microsoft Windows 11 Version 24H2 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 29% 13 Aug 2024
8.8 high CVE-2024-38189 KEV Microsoft Office 2019 Microsoft Project Remote Code Execution Vulnerability 8.2% 13 Aug 2024
7.5 high CVE-2024-38178 KEV Microsoft Windows 11 Version 24H2 Scripting Engine Memory Corruption Vulnerability 41% 13 Aug 2024
7.8 high CVE-2024-38107 KEV Microsoft Windows 10 Version 1809 Windows Power Dependency Coordinator Elevation of Privilege Vulnerability 1.6% 13 Aug 2024
7.0 high CVE-2024-38106 KEV Microsoft Windows 10 Version 1809 Windows Kernel Elevation of Privilege Vulnerability 6.3% 13 Aug 2024
7.2 high CVE-2024-41710 KEV mitel 6940_sip_firmware A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system. 42% 12 Aug 2024
6.1 medium CVE-2024-27443 KEV zimbra collaboration An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code. 24% 12 Aug 2024
7.2 high CVE-2024-7694 KEV TeamT5 ThreatSonar Anti-Ransomware ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server. 1.8% 12 Aug 2024
9.8 critical CVE-2024-7399 KEV Samsung Electronics MagicINFO 9 Server Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority. 92% 12 Aug 2024
9.3 critical CVE-2024-42009 KEV roundcube webmail A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php. 83% 5 Aug 2024
9.8 critical CVE-2024-38856 KEV Apache Software Foundation Apache OFBiz Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints). 99% 5 Aug 2024
9.8 critical CVE-2023-45249 KEV Acronis Cyber Infrastructure Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132. 53% 24 Jul 2024
7.5 high CVE-2024-21182 KEV Oracle Corporation WebLogic Server Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). 74% 16 Jul 2024
9.3 critical CVE-2024-5910 KEV Palo Alto Networks Expedition Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue. 92% 10 Jul 2024
9.2 critical CVE-2024-5217 KEV ServiceNow Now Platform ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible. >99% 10 Jul 2024
9.3 critical CVE-2024-4879 KEV ServiceNow Now Platform ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible. >99% 10 Jul 2024
7.5 high CVE-2024-38112 KEV Microsoft Windows 10 Version 22H2 Windows MSHTML Platform Spoofing Vulnerability 84% 9 Jul 2024
7.2 high CVE-2024-38094 KEV Microsoft SharePoint Enterprise Server 2016 Microsoft SharePoint Remote Code Execution Vulnerability 51% 9 Jul 2024