CVE Database

Comprehensive vulnerability intelligence with advanced analytics

6.1

CVE-2024-11182

Medium KEV

An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window.

Published: Nov 15, 2024
Modified: Oct 30, 2025
Product: mdaemon mdaemon
EPSS: 11.89%
View Details
9.8

CVE-2024-11120

Critical KEV

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.

Published: Nov 15, 2024
Modified: Oct 30, 2025
Product: geovision gv-vs11_firmware
EPSS: 66.14%
View Details
7.3

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

Published: Nov 13, 2024
Modified: Oct 23, 2025
Product: google android
EPSS: 0.12%
View Details
6.5

CVE-2024-43451

Medium KEV

NTLM Hash Disclosure Spoofing Vulnerability

Published: Nov 12, 2024
Modified: Oct 28, 2025
Product: microsoft windows_10_1507
EPSS: 89.93%
View Details
5.8

CVE-2024-20481

Medium KEV

A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion. An attacker could…

Published: Oct 23, 2024
Modified: Oct 28, 2025
Product: cisco adaptive_security_appliance_software
EPSS: 11.12%
View Details
9.1

CVE-2024-41713

Critical KEV

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data…

Published: Oct 21, 2024
Modified: Nov 04, 2025
Product: mitel micollab
EPSS: 93.91%
View Details
6.5

CVE-2024-43573

Medium KEV

Windows MSHTML Platform Spoofing Vulnerability

Published: Oct 08, 2024
Modified: Oct 30, 2025
Product: microsoft windows_10_1507
EPSS: 18.56%
View Details
7.8

Microsoft Management Console Remote Code Execution Vulnerability

Published: Oct 08, 2024
Modified: Oct 30, 2025
Product: microsoft windows_10_1507
EPSS: 41.43%
View Details
7.8

Memory corruption while maintaining memory maps of HLOS memory.

Published: Oct 07, 2024
Modified: Oct 28, 2025
Product: qualcomm qca6595_firmware
EPSS: 2.34%
View Details
10.0

CVE-2024-45519

Critical KEV

The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.

Published: Oct 02, 2024
Modified: Nov 04, 2025
Product: synacor zimbra_collaboration_suite
EPSS: 94.14%
View Details
7.5

The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.

Published: Sep 17, 2024
Modified: Oct 31, 2025
Product: vmware cloud_foundation
EPSS: 29.53%
View Details
9.8

CVE-2024-38812

Critical KEV

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

Published: Sep 17, 2024
Modified: Oct 31, 2025
Product: vmware cloud_foundation
EPSS: 79.50%
View Details
8.8

Windows MSHTML Platform Spoofing Vulnerability

Published: Sep 10, 2024
Modified: Oct 28, 2025
Product: microsoft windows_10_1507
EPSS: 15.75%
View Details
7.3

Microsoft Publisher Security Feature Bypass Vulnerability

Published: Sep 10, 2024
Modified: Oct 28, 2025
Product: microsoft office_long_term_servicing_channel
EPSS: 1.43%
View Details
5.4

CVE-2024-38217

Medium KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

Published: Sep 10, 2024
Modified: Oct 28, 2025
Product: microsoft windows_10_1507
EPSS: 13.57%
View Details
7.8

Windows Installer Elevation of Privilege Vulnerability

Published: Sep 10, 2024
Modified: Oct 28, 2025
Product: microsoft windows_10_1507
EPSS: 12.83%
View Details
9.8

CVE-2024-40711

Critical KEV

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

Published: Sep 07, 2024
Modified: Oct 30, 2025
Product: veeam veeam_backup_\&_replication
EPSS: 68.20%
View Details
9.8

CVE-2024-20439

Critical KEV

A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this vulnerability by using the static…

Published: Sep 04, 2024
Modified: Oct 28, 2025
Product: cisco smart_license_utility
EPSS: 84.89%
View Details
7.5

Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

Published: Sep 04, 2024
Modified: Oct 23, 2025
Product: apache ofbiz
EPSS: 94.15%
View Details
9.8

CVE-2024-40766

Critical KEV

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and…

Published: Aug 23, 2024
Modified: Oct 31, 2025
Product: sonicwall sonicos
EPSS: 4.02%
View Details
7.2

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a…

Published: Aug 22, 2024
Modified: Oct 30, 2025
Product: versa-networks versa_director
EPSS: 5.97%
View Details
9.1

CVE-2024-28987

Critical KEV

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

Published: Aug 21, 2024
Modified: Oct 27, 2025
Product: solarwinds web_help_desk
EPSS: 94.29%
View Details
9.8

CVE-2024-28986

Critical KEV

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing.   However,…

Published: Aug 13, 2024
Modified: Oct 27, 2025
Product: solarwinds web_help_desk
EPSS: 81.54%
View Details
6.5

CVE-2024-38213

Medium KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

Published: Aug 13, 2024
Modified: Oct 28, 2025
Product: microsoft windows_10_1507
EPSS: 59.32%
View Details