VulnSea

Tagged “kev”

CVEs tagged kev, newest first.

338 CVEsRSS

CVE-2024-41713Critical· 9.1CISA KEVPoC
1y ago

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A succes…

▾ Hadalmitel · micollabEPSS 98%via NVD
CVE-2024-9680Critical· 9.8CISA KEV0dayPoC
1y ago

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.…

▾ Hadalmozilla · firefoxEPSS 23%via NVD
CVE-2024-40766Critical· 9.8CISA KEVPoC
2y ago

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects So…

▾ Hadalsonicwall · sonicosEPSS 18%via NVD
CVE-2024-35250High· 7.8CISA KEVPoC
2y ago

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 25%via NVD
CVE-2024-30088High· 7.0CISA KEVPoC
2y ago

Windows Kernel Elevation of Privilege Vulnerability

Windows Kernel Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 68%via NVD
CVE-2024-23692Critical· 9.8CISA KEVPoC
2y ago

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending…

▾ Hadalrejetto · http_file_serverEPSS 99%via NVD
CVE-2024-24919High· 8.6CISA KEVPoC
2y ago

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerab…

▾ Abyssalcheckpoint · cloudguard_network_securityEPSS 100%via NVD
CVE-2023-50224Medium· 6.5CISA KEV0day
2y ago

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Au…

▾ Midnighttp-link · tl-wr841n_firmwareEPSS 16%via NVD
CVE-2024-1212Critical· 10.0CISA KEVPoC
2y ago

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

▾ Hadalprogress · loadmasterEPSS 95%via NVD
CVE-2024-21338High· 7.8CISA KEV0dayPoC
2y ago

Windows Kernel Elevation of Privilege Vulnerability

Windows Kernel Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1809EPSS 60%via NVD
CVE-2024-21762Critical· 9.8CISA KEV0dayPoC
2y ago

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7…

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7…

▾ Hadalfortinet · fortiproxyEPSS 83%via NVD
CVE-2021-43798High· 7.5CISA KEVPoC
2y ago

Grafana path traversal

Grafana path traversal

▾ Abyssalgrafana · github.com/grafana/grafanaEPSS 89%via OSV
CVE-2024-1086High· 7.8CISA KEVPoC
2y ago

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …

▾ Abyssalnetapp · h300s_firmwareEPSS 28%via NVD
CVE-2024-21893High· 8.2CISA KEV0dayPoC
2y ago

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…

▾ Abyssalivanti · connect_secureEPSS 100%via NVD
CVE-2024-21887Critical· 9.1CISA KEV0dayPoC
2y ago

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…

▾ Hadalivanti · connect_secureEPSS 100%via NVD
CVE-2023-46805High· 8.2CISA KEV0dayPoC
2y ago

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

▾ Abyssalivanti · connect_secureEPSS 100%via NVD
CVE-2022-2586Medium· 5.3CISA KEV0dayPoC
2y ago

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

▾ Midnightlinux · linux_kernelEPSS 10%via NVD
CVE-2023-49105Critical· 9.8CISA KEVPoC
2y ago

An issue was discovered in ownCloud owncloud/core before 10.13.1

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs b…

▾ Hadalowncloud · owncloud_serverEPSS 43%via NVD
CVE-2023-47246Critical· 9.8CISA KEV0dayPoC
2y ago

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

▾ Hadalsysaid · sysaidEPSS 99%via NVD
CVE-2023-4966Critical· 9.4CISA KEVPoC
2y ago

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

▾ Hadalcitrix · netscaler_application_delivery_controllerEPSS 100%via NVD
CVE-2023-4863High· 8.8CISA KEV0dayPoC
3y ago

libwebp: OOB write in BuildHuffmanTable

libwebp: OOB write in BuildHuffmanTable

▾ Abyssallibwebp-sys2 · libwebp-sys2EPSS 100%via OSV
CVE-2023-20269Medium· 5.0CISA KEV
3y ago

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an …

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an …

▾ Midnightcisco · adaptive_security_appliance_softwareEPSS 25%via NVD
CVE-2023-28434High· 8.8CISA KEVPoC
3y ago

Privilege Escalation on Linux/MacOS

Privilege Escalation on Linux/MacOS

▾ Abyssalminio · github.com/minio/minioEPSS 7.9%via OSV
CVE-2023-41266High· 8.2CISA KEVPoC
3y ago

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an un…

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an un…

▾ Abyssalqlik · qlik_senseEPSS 85%via NVD
CVE-2023-41265Critical· 9.6CISA KEVPoC
3y ago

An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier all…

An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier all…

▾ Hadalqlik · qlik_senseEPSS 88%via NVD
CVE-2023-4346High· 7.5CISA KEV
3y ago

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the device…

▾ Abyssalknx · connection_authorizationEPSS 1.3%via NVD
CVE-2023-38831High· 7.8CISA KEV0dayPoC
3y ago

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and al…

▾ Abyssalrarlab · winrarEPSS 100%via NVD
CVE-2023-38950High· 7.5CISA KEVPoC
3y ago

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.

▾ Abyssalzkteco · biotimeEPSS 92%via NVD
CVE-2023-35078Critical· 9.8CISA KEV0dayPoC
3y ago

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

▾ Hadalivanti · endpoint_manager_mobileEPSS 100%via NVD
CVE-2023-3519Critical· 9.8CISA KEV0dayPoC
3y ago

Unauthenticated remote code execution

Unauthenticated remote code execution

▾ Hadalcitrix · netscaler_application_delivery_controllerEPSS 100%via NVD
CVEs tagged “kev” — page 6 · VulnSea