KEV Catalog CVEs

Attaxion maintains a list of Common Vulnerabilities and Exposures (CVEs) and their affected products. 243,000+ CVEs are indexed from NVD, and those that have been added to the Known Exploited Vulnerabilities (KEV) Catalog recently are listed below.

❮ Previous Page -10 of 21 · 207 total CVEs Next ❯

CVE-2024-39717

HIGH

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a…

CVE-2024-28986

CRITICAL

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing.   However,…

CVE-2024-38106

HIGH

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-38107

HIGH

Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

CVE-2024-38178

HIGH

Scripting Engine Memory Corruption Vulnerability

CVE-2024-38189

HIGH

Microsoft Project Remote Code Execution Vulnerability

CVE-2024-38193

HIGH

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2024-38213

MEDIUM

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2024-36971

HIGH

In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first clear sk->sk_dst_cache, then call dst_release(old_dst). Note that sk_dst_reset(sk) is implementing this protocol correctly,…

CVE-2024-32113

CRITICAL

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.

❮ Previous Page -10 of 21 · 207 total CVEs Next ❯