1,734 totalEPSS avg 50.3%

KEVKnown Exploited Vulnerabilities

CISA’s actively-exploited catalogue · refreshed weekly · authored by Adam Lundqvist

Showing 1,734 of 1,734 · page 12 of 35

CVEVendor / ProductTitleKEV addedEPSS
CVE-2019-0344SAP / Commerce CloudSAP Commerce Cloud Deserialization of Untrusted Data Vulnerability2024-09-30
7.1%
CVE-2020-15415DrayTek / Multiple Vigor RoutersDrayTek Multiple Vigor Routers OS Command Injection Vulnerability2024-09-30
84.5%
CVE-2023-25280D-Link / DIR-820 RouterD-Link DIR-820 Router OS Command Injection Vulnerability2024-09-30
97.9%
CVE-2024-7593Ivanti / Virtual Traffic ManagerIvanti Virtual Traffic Manager Authentication Bypass Vulnerability2024-09-24
100.0%
CVE-2024-8963Ivanti / Cloud Services Appliance (CSA)Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability2024-09-19
98.6%
CVE-2020-0618Microsoft / SQL ServerMicrosoft SQL Server Reporting Services Remote Code Execution Vulnerability2024-09-18
99.0%
CVE-2020-14644Oracle / WebLogic ServerOracle WebLogic Server Remote Code Execution Vulnerability2024-09-18
94.5%
CVE-2022-21445Oracle / ADF FacesOracle ADF Faces Deserialization of Untrusted Data Vulnerability2024-09-18
62.5%
CVE-2024-27348Apache / HugeGraph-ServerApache HugeGraph-Server Improper Access Control Vulnerability2024-09-18
99.2%
CVE-2013-0643Adobe / Flash PlayerAdobe Flash Player Incorrect Default Permissions Vulnerability2024-09-17
10.5%
CVE-2013-0648Adobe / Flash PlayerAdobe Flash Player Code Execution Vulnerability2024-09-17
11.1%
CVE-2014-0497Adobe / Flash PlayerAdobe Flash Player Integer Underflow Vulnerablity2024-09-17
99.9%
CVE-2014-0502Adobe / Flash PlayerAdobe Flash Player Double Free Vulnerablity2024-09-17
24.8%
CVE-2024-43461Microsoft / WindowsMicrosoft Windows MSHTML Platform Spoofing Vulnerability2024-09-16
54.5%
CVE-2024-6670Progress / WhatsUp GoldProgress WhatsUp Gold SQL Injection Vulnerability2024-09-16
93.0%
CVE-2024-8190Ivanti / Cloud Services ApplianceIvanti Cloud Services Appliance OS Command Injection Vulnerability2024-09-13
88.5%
CVE-2024-38014Microsoft / WindowsMicrosoft Windows Installer Improper Privilege Management Vulnerability2024-09-10
6.3%
CVE-2024-38217Microsoft / WindowsMicrosoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnera…2024-09-10
10.0%
CVE-2024-38226Microsoft / PublisherMicrosoft Publisher Protection Mechanism Failure Vulnerability2024-09-10
2.7%
CVE-2016-3714ImageMagick / ImageMagickImageMagick Improper Input Validation Vulnerability2024-09-09
97.5%
CVE-2017-1000253Linux / KernelLinux Kernel PIE Stack Buffer Corruption Vulnerability 2024-09-09
10.7%
CVE-2024-40766SonicWall / SonicOSSonicWall SonicOS Improper Access Control Vulnerability2024-09-09
18.4%
CVE-2021-20123DrayTek / VigorConnectDraytek VigorConnect Path Traversal Vulnerability 2024-09-03
90.2%
CVE-2021-20124DrayTek / VigorConnectDraytek VigorConnect Path Traversal Vulnerability 2024-09-03
96.3%
CVE-2024-7262Kingsoft / WPS OfficeKingsoft WPS Office Path Traversal Vulnerability2024-09-03
2.9%
CVE-2024-7965Google / Chromium V8Google Chromium V8 Inappropriate Implementation Vulnerability2024-08-28
18.5%
CVE-2024-38856Apache / OFBizApache OFBiz Incorrect Authorization Vulnerability2024-08-27
99.4%
CVE-2024-7971Google / Chromium V8Google Chromium V8 Type Confusion Vulnerability2024-08-26
21.1%
CVE-2024-39717Versa / DirectorVersa Director Dangerous File Type Upload Vulnerability2024-08-23
4.0%
CVE-2021-31196Microsoft / Exchange ServerMicrosoft Exchange Server Information Disclosure Vulnerability2024-08-21
54.1%
CVE-2021-33044Dahua / IP Camera FirmwareDahua IP Camera Authentication Bypass Vulnerability2024-08-21
100.0%
CVE-2021-33045Dahua / IP Camera FirmwareDahua IP Camera Authentication Bypass Vulnerability2024-08-21
99.6%
CVE-2022-0185Linux / KernelLinux Kernel Heap-Based Buffer Overflow Vulnerability2024-08-21
25.2%
CVE-2024-23897Jenkins / Jenkins Command Line Interface (CLI)Jenkins Command Line Interface (CLI) Path Traversal Vulnerability2024-08-19
100.0%
CVE-2024-28986SolarWinds / Web Help DeskSolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability2024-08-15
84.6%
CVE-2024-38106Microsoft / WindowsMicrosoft Windows Kernel Privilege Escalation Vulnerability2024-08-13
6.3%
CVE-2024-38107Microsoft / WindowsMicrosoft Windows Power Dependency Coordinator Privilege Escalation Vulnerabi…2024-08-13
1.6%
CVE-2024-38178Microsoft / WindowsMicrosoft Windows Scripting Engine Memory Corruption Vulnerability2024-08-13
41.4%
CVE-2024-38189Microsoft / ProjectMicrosoft Project Remote Code Execution Vulnerability 2024-08-13
8.2%
CVE-2024-38193Microsoft / WindowsMicrosoft Windows Ancillary Function Driver for WinSock Privilege Escalation …2024-08-13
28.7%
CVE-2024-38213Microsoft / WindowsMicrosoft Windows SmartScreen Security Feature Bypass Vulnerability2024-08-13
13.6%
CVE-2024-32113Apache / OFBizApache OFBiz Path Traversal Vulnerability2024-08-07
99.9%
CVE-2024-36971Android / KernelAndroid Kernel Remote Code Execution Vulnerability2024-08-07
2.7%
CVE-2018-0824Microsoft / WindowsMicrosoft COM for Windows Deserialization of Untrusted Data Vulnerability2024-08-05
73.2%
CVE-2024-37085VMware / ESXiVMware ESXi Authentication Bypass Vulnerability2024-07-30
26.8%
CVE-2023-45249Acronis / Cyber Infrastructure (ACI)Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability2024-07-29
53.3%
CVE-2024-4879ServiceNow / Utah, Vancouver, and Washington DC Now PlatformServiceNow Improper Input Validation Vulnerability2024-07-29
100.0%
CVE-2024-5217ServiceNow / Utah, Vancouver, and Washington DC Now PlatformServiceNow Incomplete List of Disallowed Inputs Vulnerability2024-07-29
99.6%
CVE-2012-4792Microsoft / Internet ExplorerMicrosoft Internet Explorer Use-After-Free Vulnerability2024-07-23
78.8%
CVE-2024-39891Twilio / AuthyTwilio Authy Information Disclosure Vulnerability2024-07-23
1.7%
Sourced from CISA Known Exploited Vulnerabilities — current weekly refresh. EPSS scores from FIRST.org via epss.cyentia.com. Curated by Adam Lundqvist, Founder at SQUR.