Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2024-38045 |
|
Windows TCP/IP Remote Code Execution Vulnerability
Windows TCP/IP Remote Code Execution Vulnerability
|
| CVE-2024-37338 |
|
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
|
| CVE-2024-37339 |
|
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
|
| CVE-2024-37340 |
|
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
|
| CVE-2024-37335 |
|
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
|
| CVE-2024-26186 |
|
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
|
| CVE-2024-26191 |
|
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
|
| CVE-2024-21416 |
|
Windows TCP/IP Remote Code Execution Vulnerability
Windows TCP/IP Remote Code Execution Vulnerability
|
| CVE-2024-6445 |
|
Path Traversal in path-traversal (CVE-2024-6445)
path traversal in path-traversal (CVE-2024-6445). Confidential information can be exposed externally.
|
| CVE-2024-8418 |
|
Vulnerability in dos (CVE-2024-8418)
vulnerability in dos (CVE-2024-8418). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-6119 |
|
Vulnerability in dos (CVE-2024-6119)
vulnerability in dos (CVE-2024-6119). Risk of unauthorized operations or information disclosure. Exploitable via ``otherName``.
|
| CVE-2023-29929 |
|
Out-of-Bounds Write in dos (CVE-2023-29929)
out-of-bounds write in dos (CVE-2023-29929). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-6508 |
|
Vulnerability in csrf (CVE-2024-6508)
vulnerability in csrf (CVE-2024-6508). Successful exploitation can lead to full system takeover.
|
| CVE-2021-31196 KEV |
|
[KEV] Vulnerability in Microsoft exchange-server (CVE-2021-31196)
vulnerability in Microsoft exchange-server (CVE-2021-31196). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2024-38884 |
|
Authorization Flaw in horizoncloud (CVE-2024-38884)
vulnerability in horizoncloud (CVE-2024-38884). Successful exploitation can lead to full system takeover.
|
| CVE-2024-37857 |
|
SQL Injection in sqli (CVE-2024-37857)
SQL injection in sqli (CVE-2024-37857). Successful exploitation can lead to full system takeover.
|
| CVE-2024-41628 |
|
Path Traversal in path-traversal (CVE-2024-41628)
path traversal in path-traversal (CVE-2024-41628). Confidential information can be exposed externally.
|
| CVE-2024-21527 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2024-21527)
SSRF in ssrf (CVE-2024-21527). Confidential information can be exposed externally.
|
| CVE-2024-4944 |
|
Command Injection in privilege-escalation (CVE-2024-4944)
command injection in privilege-escalation (CVE-2024-4944). Successful exploitation can lead to full system takeover.
|
| CVE-2024-5974 |
|
A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with...
A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with...
|
| CVE-2024-5971 |
|
A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not s...
A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of the chunked response. This results in uncontrolled resource co...
|
| CVE-2024-6409 |
|
Vulnerability in CVE-2024-6409 (CVE-2024-6409)
vulnerability in CVE-2024-6409 (CVE-2024-6409). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-5154 |
|
Path Traversal in path-traversal (CVE-2024-5154)
path traversal in path-traversal (CVE-2024-5154). Confidential information can be exposed externally.
|
| CVE-2024-35249 |
|
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
|
| CVE-2024-35252 |
|
Azure Storage Movement Client Library Denial of Service Vulnerability
Azure Storage Movement Client Library Denial of Service Vulnerability
|
| CVE-2024-30104 |
|
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
|
| CVE-2024-30101 |
|
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
|
| CVE-2024-30103 |
|
Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
|
| CVE-2024-30095 |
|
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
|
| CVE-2024-30097 |
|
Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
|
| CVE-2024-30094 |
|
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
|
| CVE-2024-30083 |
|
Windows Standards-Based Storage Management Service Denial of Service Vulnerability
Windows Standards-Based Storage Management Service Denial of Service Vulnerability
|
| CVE-2024-30074 |
|
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
|
| CVE-2024-30075 |
|
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
|
| CVE-2024-30077 |
|
Windows OLE Remote Code Execution Vulnerability
Windows OLE Remote Code Execution Vulnerability
|
| CVE-2024-30078 |
|
Windows Wi-Fi Driver Remote Code Execution Vulnerability
Windows Wi-Fi Driver Remote Code Execution Vulnerability
|
| CVE-2024-30072 |
|
Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability
Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability
|
| CVE-2024-30070 |
|
DHCP Server Service Denial of Service Vulnerability
DHCP Server Service Denial of Service Vulnerability
|
| CVE-2024-30062 |
|
Windows Standards-Based Storage Management Service Remote Code Execution Vulnerability
Windows Standards-Based Storage Management Service Remote Code Execution Vulnerability
|
| CVE-2024-1086 KEV |
|
[KEV] Use-After-Free in Linux kernel (CVE-2024-1086)
vulnerability in Linux kernel (CVE-2024-1086). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2024-3727 |
|
Vulnerability in path-traversal (CVE-2024-3727)
vulnerability in path-traversal (CVE-2024-3727). Successful exploitation can lead to full system takeover.
|
| CVE-2024-33601 |
|
Vulnerability in dos (CVE-2024-33601)
vulnerability in dos (CVE-2024-33601). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-1139 |
|
A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a re...
A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret.
|
| CVE-2024-20353 KEV |
|
[KEV] Vulnerability in Cisco adaptive-security-appliance-asa-and-firepower-threat-defense-ftd (CVE-2024-20353)
vulnerability in Cisco adaptive-security-appliance-asa-and-firepower-threat-defense-ftd (CVE-2024-20353). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-26898 |
|
Use-After-Free in dos (CVE-2024-26898)
vulnerability in dos (CVE-2024-26898). Successful exploitation can lead to full system takeover. Exploitable via ``skbtxq``.
|
| CVE-2024-26257 |
|
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
|
| CVE-2024-28714 |
|
SQL Injection in sqli (CVE-2024-28714)
SQL injection in sqli (CVE-2024-28714). Confidential information can be exposed externally.
|
| CVE-2023-52494 |
|
Out-of-Bounds Write in dos (CVE-2023-52494)
out-of-bounds write in dos (CVE-2023-52494). Successful exploitation can lead to full system takeover.
|
| CVE-2024-27289 |
|
pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the following conditions are met: the non-default simple protocol is used; a placeholder for...
pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the following conditions are met: the non-default simple protocol is used; a placeholder for a numeric value must be immediately preceded by a minus; there must be a second placeholder for a s...
|
| CVE-2023-33677 |
|
SQL Injection in sqli (CVE-2023-33677)
SQL injection in sqli (CVE-2023-33677). Confidential information can be exposed externally.
|