Exploited vulnerabilities

CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.

46,877 CVEs · 1,734 known exploited · CVE data updated 2 hours ago · EPSS 1 hour ago

1,734 results · page 25 of 87 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Published
9.8 critical CVE-2024-4358 KEV Progress Software Corporation Telerik Report Server In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability. 97% 29 May 2024
8.6 high CVE-2024-24919 KEV checkpoint Check Point Quantum Gateway, Spark Gateway and CloudGuard Network Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available. >99% 28 May 2024
9.6 critical CVE-2024-5274 KEV Google Chrome Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 7.5% 28 May 2024
8.7 high CVE-2024-4978 KEV Justice AV Solutions Viewer Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands. 27% 23 May 2024
9.6 critical CVE-2024-4947 KEV Google Chrome Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 15% 15 May 2024
7.8 high CVE-2024-30051 KEV Microsoft Windows 10 Version 1809 Windows DWM Core Library Elevation of Privilege Vulnerability 5.7% 14 May 2024
8.8 high CVE-2024-30040 KEV Microsoft Windows 10 Version 1809 Windows MSHTML Platform Security Feature Bypass Vulnerability 3.9% 14 May 2024
8.8 high CVE-2024-4761 KEV Google Chrome Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) 11% 14 May 2024
9.6 critical CVE-2024-4671 KEV Google Chrome Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 8.3% 14 May 2024
9.8 critical CVE-2024-32113 KEV Apache Software Foundation Apache OFBiz Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue. >99% 8 May 2024
6.5 medium CVE-2023-50224 KEV TP-Link TL-WR841N TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899. 16% 3 May 2024
6.0 medium CVE-2024-20359 KEV Cisco Adaptive Security Appliance (ASA) Software A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability. This vulnerability is due to improper validation of a file when it is read from system flash memory. An attacker could exploit this vulnerability by copying a crafted file to the disk0: file system of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the affected device after the next reload of the device, which could alter system behavior. Because the injected code could persist across device reboots, Cisco has raised the Security Impact Rating (SIR) of this advisory from Medium to High. 19% 24 Apr 2024
8.6 high CVE-2024-20353 KEV Cisco Adaptive Security Appliance (ASA) Software A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a device. A successful exploit could allow the attacker to cause a DoS condition when the device reloads. 71% 24 Apr 2024
10.0 critical CVE-2024-4040 KEV CrushFTP A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server. >99% 22 Apr 2024
9.8 critical CVE-2024-27348 KEV Apache Software Foundation Apache HugeGraph-Server RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue. 99% 22 Apr 2024
10.0 critical CVE-2024-3400 KEV Palo Alto Networks PAN-OS A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability. >99% 12 Apr 2024
8.8 high CVE-2024-29988 KEV Microsoft Windows 10 Version 1809 SmartScreen Prompt Security Feature Bypass Vulnerability 45% 9 Apr 2024
7.8 high CVE-2024-29748 KEV Google Android there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. 0.67% 5 Apr 2024
5.5 medium CVE-2024-29745 KEV Google Android there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. 0.48% 5 Apr 2024
9.8 critical CVE-2024-3273 KEV D-Link DNS-320L ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced. >99% 4 Apr 2024