CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 2mo ago | 8.8 | An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective. |
| 2mo ago | 7.5 | SpiderControl SCADA Web Server has a vulnerability that could allow an attacker to upload specially crafted malicious files without authentication. |
| Exploit 2mo ago | 7.4 | Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access credentials of last authenticated user via OpenID or OAuth2 where the authentication URL did not include redirect query string. This happens because on that endpoint for both OpenId and Oauth2 Directus is using the respond middleware, which by default will try to cache GET requests that met some conditions. Although, those conditions do not include this scenario, when an unauthenticated request returns user credentials. This vulnerability is fixed in 10.13.3 and 11.1.0. |
| Exploit 2mo ago | 7.2 | An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file. |
| 2mo ago | 8 | Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unauthenticated factory mode reset and command injection leads to information exposure and root shell access. |
| Exploit 2mo ago | 7.3 | Windows libarchive Remote Code Execution Vulnerability |
| 2mo ago | 7.8 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability |
| Exploit 2mo ago | 8.5 | Microsoft Power Automate Desktop Remote Code Execution Vulnerability |
| 2mo ago | 7.6 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| 2mo ago | 7.3 | Microsoft Windows Admin Center Information Disclosure Vulnerability |
| 2mo ago | 7.6 | Microsoft SQL Server Information Disclosure Vulnerability |
| 2mo ago | 7.3 | Azure Network Watcher VM Agent Elevation of Privilege Vulnerability |
| Exploit 2mo ago | 8.8 | Azure CycleCloud Remote Code Execution Vulnerability |
| Exploit 2mo ago | 7.5 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
| 2mo ago | 7.8 | Microsoft Excel Elevation of Privilege Vulnerability |
| Exploit 2mo ago | 7.2 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| Exploit 2mo ago | 7.8 | Microsoft Office Visio Remote Code Execution Vulnerability |
| KEV 2mo ago | 8.8 | Windows MSHTML Platform Spoofing Vulnerability |
| 2mo ago | 7.7 | Windows Networking Information Disclosure Vulnerability |
| 2mo ago | 7.8 | Windows Setup and Deployment Elevation of Privilege Vulnerability |
| 2mo ago | 8.8 | Windows Remote Desktop Licensing Service Spoofing Vulnerability |
| Exploit 2mo ago | 7.1 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
| Exploit 2mo ago | 7.5 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
| Exploit 2mo ago | 8.8 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
| Exploit 2mo ago | 8.8 | Microsoft Management Console Remote Code Execution Vulnerability |
| 2mo ago | 7.5 | Microsoft AllJoyn API Information Disclosure Vulnerability |
| 2mo ago | 7.8 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
| 2mo ago | 7.8 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
| 2mo ago | 7.8 | Windows Graphics Component Elevation of Privilege Vulnerability |
| 2mo ago | 7.8 | Windows Graphics Component Elevation of Privilege Vulnerability |