Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2024-21364

Description: Microsoft Azure Site Recovery Elevation of Privilege Vulnerability

CVSS: CRITICAL (9.3)

EPSS Score: 0.05%

Source: CVE
January 1st, 2025 (4 months ago)

CVE-2024-21334

Description: Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

CVSS: CRITICAL (9.8)

EPSS Score: 0.05%

Source: CVE
January 1st, 2025 (4 months ago)

CVE-2024-21326

Description: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVSS: CRITICAL (9.6)

EPSS Score: 0.05%

Source: CVE
January 1st, 2025 (4 months ago)

CVE-2024-13061

Description: The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be used to log into the system.

CVSS: CRITICAL (9.8)

EPSS Score: 0.05%

Source: CVE
January 1st, 2025 (4 months ago)

CVE-2024-12108

Description: In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.

CVSS: CRITICAL (9.6)

EPSS Score: 0.07%

Source: CVE
January 1st, 2025 (4 months ago)

CVE-2024-12106

Description: In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.

CVSS: CRITICAL (9.4)

EPSS Score: 0.05%

Source: CVE
January 1st, 2025 (4 months ago)

CVE-2024-0057

Description: NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability

CVSS: CRITICAL (9.1)

EPSS Score: 0.15%

Source: CVE
January 1st, 2025 (4 months ago)

CVE-2024-56799

Description: Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, some API routes may be publicly accessible when they should require authentication. This vulnerability has been patched in v0.2.7.

CVSS: CRITICAL (10.0)

EPSS Score: 0.04%

Source: CVE
December 31st, 2024 (4 months ago)

CVE-2024-47926

Description: Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSS: CRITICAL (9.8)

EPSS Score: 0.04%

Source: CVE
December 31st, 2024 (4 months ago)

CVE-2024-47919

Description: Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVSS: CRITICAL (9.8)

EPSS Score: 0.04%

Source: CVE
December 31st, 2024 (4 months ago)