CVE Database

Comprehensive vulnerability intelligence with advanced analytics

5.8

CVE-2025-25181

Medium KEV

A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.

Published: Feb 03, 2025
Modified: Nov 05, 2025
Product: advantive veracore
EPSS: 81.69%
View Details
9.9

CVE-2024-57968

Critical KEV

Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.

Published: Feb 03, 2025
Modified: Nov 04, 2025
Product: advantive veracore
EPSS: 25.73%
View Details
7.0

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of…

Published: Jan 25, 2025
Modified: Oct 27, 2025
Product: 7-zip 7-zip
EPSS: 32.63%
View Details
9.8

CVE-2025-23006

Critical KEV

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.

Published: Jan 23, 2025
Modified: Oct 31, 2025
Product: sonicwall sma7200_firmware
EPSS: 52.07%
View Details
8.0

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security…

Published: Jan 18, 2025
Modified: Oct 24, 2025
Product: craftcms craft_cms
EPSS: 4.66%
View Details
7.5

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

Published: Jan 15, 2025
Modified: Nov 04, 2025
Product: simple-help simplehelp
EPSS: 93.85%
View Details
7.8

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

Published: Jan 14, 2025
Modified: Oct 27, 2025
Product: microsoft windows_10_21h2
EPSS: 4.80%
View Details
7.8

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

Published: Jan 14, 2025
Modified: Oct 27, 2025
Product: microsoft windows_10_21h2
EPSS: 3.80%
View Details
9.8

CVE-2024-13161

Critical KEV

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

Published: Jan 14, 2025
Modified: Oct 24, 2025
Product: ivanti endpoint_manager
EPSS: 91.31%
View Details
9.8

CVE-2024-13160

Critical KEV

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

Published: Jan 14, 2025
Modified: Oct 24, 2025
Product: ivanti endpoint_manager
EPSS: 92.82%
View Details
9.8

CVE-2024-13159

Critical KEV

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

Published: Jan 14, 2025
Modified: Oct 24, 2025
Product: ivanti endpoint_manager
EPSS: 94.14%
View Details
9.8

CVE-2024-55591

Critical KEV

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

Published: Jan 14, 2025
Modified: Oct 24, 2025
Product: fortinet fortiproxy
EPSS: 93.66%
View Details
9.8

CVE-2024-53704

Critical KEV

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

Published: Jan 09, 2025
Modified: Oct 31, 2025
Product: sonicwall sonicos
EPSS: 93.82%
View Details
10.0

CVE-2024-50603

Critical KEV

An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.

Published: Jan 08, 2025
Modified: Nov 05, 2025
Product: aviatrix controller
EPSS: 94.35%
View Details
7.3

A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The…

Published: Dec 27, 2024
Modified: Oct 30, 2025
Product: draytek vigor2960_firmware
EPSS: 81.09%
View Details
7.5

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

Published: Dec 27, 2024
Modified: Nov 04, 2025
Product: paloaltonetworks pan-os
EPSS: 66.59%
View Details
6.6

CVE-2024-12686

Medium KEV

A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.

Published: Dec 18, 2024
Modified: Oct 24, 2025
Product: beyondtrust privileged_remote_access
EPSS: 15.67%
View Details
9.8

CVE-2024-12356

Critical KEV

A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.

Published: Dec 17, 2024
Modified: Oct 24, 2025
Product: beyondtrust privileged_remote_access
EPSS: 93.69%
View Details
7.5

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted…

Published: Nov 27, 2024
Modified: Oct 27, 2025
Product: zyxel zld
EPSS: 34.19%
View Details
9.8

CVE-2024-11680

Critical KEV

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

Published: Nov 26, 2024
Modified: Oct 31, 2025
EPSS: 93.49%
View Details
6.1

CVE-2024-44309

Medium KEV

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a…

Published: Nov 20, 2024
Modified: Nov 04, 2025
Product: apple safari
EPSS: 0.58%
View Details
8.8

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may…

Published: Nov 20, 2024
Modified: Nov 04, 2025
Product: apple safari
EPSS: 0.94%
View Details
7.5

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can result…

Published: Nov 18, 2024
Modified: Oct 27, 2025
Product: oracle agile_product_lifecycle_management
EPSS: 69.83%
View Details
9.8

CVE-2024-0012

Critical KEV

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue…

Published: Nov 18, 2024
Modified: Nov 04, 2025
Product: paloaltonetworks pan-os
EPSS: 94.30%
View Details