CVE Database

Comprehensive vulnerability intelligence with advanced analytics

8.6

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

Published: May 28, 2024
Modified: Oct 24, 2025
Product: checkpoint quantum_spark_firmware
EPSS: 94.34%
View Details
7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

Published: May 14, 2024
Modified: Oct 28, 2025
Product: microsoft windows_10_1507
EPSS: 53.88%
View Details
8.8

Windows MSHTML Platform Security Feature Bypass Vulnerability

Published: May 14, 2024
Modified: Oct 28, 2025
Product: microsoft windows_10_1507
EPSS: 23.49%
View Details
8.8

Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

Published: May 14, 2024
Modified: Dec 23, 2025
Product: fedoraproject fedora
EPSS: 2.75%
View Details

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue…

Published: May 03, 2024
Modified: Oct 27, 2025
Product: tp-link tl-wr841n_firmware
EPSS: 2.37%
View Details
6.0

CVE-2024-20359

Medium KEV

A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges…

Published: Apr 24, 2024
Modified: Oct 28, 2025
Product: cisco adaptive_security_appliance_software
EPSS: 0.18%
View Details
8.6

A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete…

Published: Apr 24, 2024
Modified: Oct 28, 2025
Product: cisco adaptive_security_appliance_software
EPSS: 19.54%
View Details
9.8

CVE-2024-4040

Critical KEV

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

Published: Apr 22, 2024
Modified: Nov 04, 2025
Product: crushftp crushftp
EPSS: 94.43%
View Details
8.8

SmartScreen Prompt Security Feature Bypass Vulnerability

Published: Apr 09, 2024
Modified: Oct 28, 2025
Product: microsoft windows_server_2019
EPSS: 66.84%
View Details
7.8

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

Published: Apr 05, 2024
Modified: Oct 24, 2025
EPSS: 0.38%
View Details
5.5

CVE-2024-29745

Medium KEV

there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Published: Apr 05, 2024
Modified: Oct 24, 2025
Product: google android
EPSS: 0.21%
View Details
7.3

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection.…

Published: Apr 04, 2024
Modified: Oct 30, 2025
Product: dlink dns-340l_firmware
EPSS: 94.43%
View Details
9.8

CVE-2024-3272

Critical KEV

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with…

Published: Apr 04, 2024
Modified: Oct 30, 2025
Product: dlink dns-340l_firmware
EPSS: 94.17%
View Details
7.5

.NET Framework Information Disclosure Vulnerability

Published: Mar 23, 2024
Modified: Oct 28, 2025
Product: microsoft .net_framework
EPSS: 93.85%
View Details
7.8

Windows Error Reporting Service Elevation of Privilege Vulnerability

Published: Mar 12, 2024
Modified: Oct 28, 2025
Product: microsoft windows_10_1507
EPSS: 34.58%
View Details
9.8

CVE-2023-48788

Critical KEV

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

Published: Mar 12, 2024
Modified: Oct 24, 2025
Product: fortinet forticlient_enterprise_management_server
EPSS: 94.16%
View Details
7.8

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 17.4 and iPadOS 17.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.

Published: Mar 05, 2024
Modified: Nov 05, 2025
Product: apple ipados
EPSS: 0.08%
View Details
7.8

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue…

Published: Mar 05, 2024
Modified: Nov 05, 2025
Product: apple ipados
EPSS: 0.10%
View Details
10.0

CVE-2024-1212

Critical KEV

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

Published: Feb 21, 2024
Modified: Oct 31, 2025
Product: progress loadmaster
EPSS: 94.35%
View Details
10.0

CVE-2024-1709

Critical KEV

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.

Published: Feb 21, 2024
Modified: Oct 24, 2025
Product: connectwise screenconnect
EPSS: 94.34%
View Details
8.8

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile…

Published: Feb 17, 2024
Modified: Oct 27, 2025
Product: oracle agile_product_lifecycle_management
EPSS: 69.04%
View Details
9.8

CVE-2024-23113

Critical KEV

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to…

Published: Feb 15, 2024
Modified: Oct 24, 2025
Product: fortinet fortiproxy
EPSS: 51.23%
View Details
9.8

CVE-2024-21413

Critical KEV

Microsoft Outlook Remote Code Execution Vulnerability

Published: Feb 13, 2024
Modified: Oct 28, 2025
Product: microsoft office_long_term_servicing_channel
EPSS: 93.39%
View Details
8.1

Internet Shortcut Files Security Feature Bypass Vulnerability

Published: Feb 13, 2024
Modified: Oct 28, 2025
Product: microsoft windows_server_2019
EPSS: 93.77%
View Details