Exploited vulnerabilities

CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.

47,281 CVEs · 1,734 known exploited · CVE data updated 19 min ago · EPSS 2 hours ago

1,734 results · page 26 of 87 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Published
9.8 critical CVE-2024-3272 KEV D-Link DNS-320L ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259283. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced. 98% 4 Apr 2024
7.5 high CVE-2024-29059 KEV Microsoft .NET Framework 4.8 .NET Framework Information Disclosure Vulnerability 99% 23 Mar 2024
7.4 high CVE-2024-20767 KEV Adobe ColdFusion ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet. 99% 18 Mar 2024
7.8 high CVE-2024-26169 KEV Microsoft Windows 10 Version 1809 Windows Error Reporting Service Elevation of Privilege Vulnerability 4.0% 12 Mar 2024
9.8 critical CVE-2023-48788 KEV Fortinet FortiClientEMS A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets. 98% 12 Mar 2024
7.8 high CVE-2024-23296 KEV Apple iOS and iPadOS A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited. 1.4% 5 Mar 2024
7.8 high CVE-2024-23225 KEV Apple iOS and iPadOS A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited. 1.5% 5 Mar 2024
7.3 high CVE-2024-27199 KEV JetBrains TeamCity In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible >99% 4 Mar 2024
9.8 critical CVE-2024-27198 KEV JetBrains TeamCity In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible >99% 4 Mar 2024
9.8 critical CVE-2024-1212 KEV Progress Software LoadMaster Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution. 95% 21 Feb 2024
10.0 critical CVE-2024-1709 KEV ConnectWise ScreenConnect ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems. >99% 21 Feb 2024
8.4 high CVE-2024-1708 KEV ConnectWise ScreenConnect ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems. 95% 21 Feb 2024
8.8 high CVE-2024-20953 KEV Oracle Corporation Agile PLM Framework Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 3.9% 17 Feb 2024
9.8 critical CVE-2024-23113 KEV Fortinet FortiSwitchManager A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets. 62% 15 Feb 2024
9.8 critical CVE-2024-21413 KEV Microsoft 365 Apps for Enterprise Microsoft Outlook Remote Code Execution Vulnerability 95% 13 Feb 2024
8.1 high CVE-2024-21412 KEV Microsoft Windows 10 Version 1809 Internet Shortcut Files Security Feature Bypass Vulnerability 99% 13 Feb 2024
9.8 critical CVE-2024-21410 KEV Microsoft Exchange Server 2016 Cumulative Update 23 Microsoft Exchange Server Elevation of Privilege Vulnerability 13% 13 Feb 2024
7.6 high CVE-2024-21351 KEV Microsoft Windows 10 Version 1507 Windows SmartScreen Security Feature Bypass Vulnerability 28% 13 Feb 2024
7.8 high CVE-2024-21338 KEV Microsoft Windows 10 Version 1809 Windows Kernel Elevation of Privilege Vulnerability 60% 13 Feb 2024
9.8 critical CVE-2024-21762 KEV Fortinet FortiProxy A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests 83% 9 Feb 2024