CVE Database

Comprehensive vulnerability intelligence with advanced analytics

8.8

Microsoft Project Remote Code Execution Vulnerability

Published: Aug 13, 2024
Modified: Oct 28, 2025
Product: microsoft office_long_term_servicing_channel
EPSS: 54.67%
View Details
7.5

Scripting Engine Memory Corruption Vulnerability

Published: Aug 13, 2024
Modified: Oct 28, 2025
Product: microsoft windows_10_1507
EPSS: 24.72%
View Details
7.8

Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

Published: Aug 13, 2024
Modified: Oct 28, 2025
Product: microsoft windows_10_1507
EPSS: 2.76%
View Details
7.0

Windows Kernel Elevation of Privilege Vulnerability

Published: Aug 13, 2024
Modified: Oct 28, 2025
Product: microsoft windows_10_1507
EPSS: 0.65%
View Details
7.2

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow…

Published: Aug 12, 2024
Modified: Nov 05, 2025
Product: mitel 6869i_sip_firmware
EPSS: 21.14%
View Details
6.1

CVE-2024-27443

Medium KEV

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing…

Published: Aug 12, 2024
Modified: Oct 31, 2025
Product: zimbra collaboration
EPSS: 32.43%
View Details
9.3

CVE-2024-42009

Critical KEV

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

Published: Aug 05, 2024
Modified: Nov 04, 2025
Product: roundcube webmail
EPSS: 90.44%
View Details
9.8

CVE-2024-38856

Critical KEV

Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check…

Published: Aug 05, 2024
Modified: Oct 23, 2025
Product: apache ofbiz
EPSS: 94.38%
View Details
9.8

CVE-2023-45249

Critical KEV

Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.

Published: Jul 24, 2024
Modified: Oct 22, 2025
Product: acronis cyber_infrastructure
EPSS: 93.34%
View Details
7.5

Windows MSHTML Platform Spoofing Vulnerability

Published: Jul 09, 2024
Modified: Oct 28, 2025
Product: microsoft windows_10_1507
EPSS: 92.82%
View Details
7.2

Microsoft SharePoint Remote Code Execution Vulnerability

Published: Jul 09, 2024
Modified: Oct 28, 2025
Product: microsoft sharepoint_server
EPSS: 69.59%
View Details
7.8

Windows Hyper-V Elevation of Privilege Vulnerability

Published: Jul 09, 2024
Modified: Oct 28, 2025
Product: microsoft windows_11_22h2
EPSS: 19.71%
View Details
5.3

CVE-2024-39891

Medium KEV

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with information about whether…

Published: Jul 02, 2024
Modified: Nov 05, 2025
Product: twilio authy
EPSS: 23.19%
View Details
9.1

CVE-2024-38475

Critical KEV

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that…

Published: Jul 01, 2024
Modified: Nov 17, 2025
Product: apache http_server
EPSS: 93.94%
View Details
6.0

CVE-2024-20399

Medium KEV

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI…

Published: Jul 01, 2024
Modified: Oct 28, 2025
Product: cisco nx-os
EPSS: 0.78%
View Details
9.8

CVE-2024-36401

Critical KEV

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users through specially crafted input against a default GeoServer installation due to unsafely evaluating property names…

Published: Jul 01, 2024
Modified: Oct 24, 2025
Product: geotools geotools
EPSS: 94.43%
View Details
6.8

CVE-2024-37085

Medium KEV

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

Published: Jun 25, 2024
Modified: Oct 30, 2025
Product: vmware cloud_foundation
EPSS: 71.92%
View Details
7.8

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

Published: Jun 13, 2024
Modified: Oct 24, 2025
Product: google android
EPSS: 0.13%
View Details
9.8

CVE-2024-34102

Critical KEV

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does…

Published: Jun 13, 2024
Modified: Oct 23, 2025
Product: adobe commerce_webhooks
EPSS: 94.10%
View Details
7.8

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

Published: Jun 11, 2024
Modified: Oct 28, 2025
Product: microsoft windows_10_1507
EPSS: 63.51%
View Details
7.0

Windows Kernel Elevation of Privilege Vulnerability

Published: Jun 11, 2024
Modified: Oct 28, 2025
Product: microsoft windows_10_1507
EPSS: 88.97%
View Details
7.8

In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first clear sk->sk_dst_cache, then call dst_release(old_dst). Note that sk_dst_reset(sk) is implementing this protocol correctly,…

Published: Jun 10, 2024
Modified: Nov 05, 2025
Product: linux linux_kernel
EPSS: 0.44%
View Details
7.8

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r34p0 through r40p0; Valhall GPU Kernel Driver:…

Published: Jun 07, 2024
Modified: Oct 23, 2025
Product: arm bifrost_gpu_kernel_driver
EPSS: 0.48%
View Details
8.8

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

Published: May 31, 2024
Modified: Oct 30, 2025
Product: ivanti endpoint_manager
EPSS: 94.09%
View Details