Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.1

    CRITICAL
    CVE-2024-11007

    Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code exe... Read more

    Affected Products : connect_secure policy_secure
    • Published: Nov. 12, 2024
    • Modified: Nov. 22, 2024
  • 4.3

    MEDIUM
    CVE-2024-10971

    Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty permission.... Read more

    Affected Products : devolutions_server
    • Published: Nov. 12, 2024
    • Modified: Jun. 27, 2025
  • 9.3

    CRITICAL
    CVE-2024-8074

    Improper Privilege Management vulnerability in Nomysoft Informatics Nomysem allows Collect Data as Provided by Users.This issue affects Nomysem: before 13.10.2024.... Read more

    Affected Products :
    • Published: Nov. 12, 2024
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2024-51566

    The NVMe driver queue processing is vulernable to guest-induced infinite loops.... Read more

    Affected Products : freebsd
    • Published: Nov. 12, 2024
    • Modified: Nov. 26, 2024
  • 6.5

    MEDIUM
    CVE-2024-51565

    The hda driver is vulnerable to a buffer over-read from a guest-controlled value.... Read more

    Affected Products : freebsd
    • Published: Nov. 12, 2024
    • Modified: Nov. 26, 2024
  • 7.5

    HIGH
    CVE-2024-51564

    A guest can trigger an infinite loop in the hda audio driver.... Read more

    Affected Products :
    • Published: Nov. 12, 2024
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2024-51563

    The virtio_vq_recordon function is subject to a time-of-check to time-of-use (TOCTOU) race condition.... Read more

    Affected Products : freebsd
    • Published: Nov. 12, 2024
    • Modified: Nov. 26, 2024
  • 6.5

    MEDIUM
    CVE-2024-51562

    The NVMe driver function nvme_opc_get_log_page is vulnerable to a buffer over-read from a guest-controlled value.... Read more

    Affected Products : freebsd
    • Published: Nov. 12, 2024
    • Modified: Nov. 26, 2024
  • 9.9

    CRITICAL
    CVE-2024-50386

    Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary storage for deploying instances. Due to missing validation checks for KVM-compatible templates in CloudStack 4.0.0 through 4.18.2.4 an... Read more

    Affected Products : cloudstack
    • Published: Nov. 12, 2024
    • Modified: Feb. 04, 2025
  • 7.5

    HIGH
    CVE-2024-45289

    The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the filename to the library was incorrect, in effect ignoring the option. Fet... Read more

    Affected Products : freebsd
    • Published: Nov. 12, 2024
    • Modified: Jan. 10, 2025
  • 7.2

    HIGH
    CVE-2024-42442

    APTIOV contains a vulnerability in the BIOS where a user or attacker may cause an improper restriction of operations within the bounds of a memory buffer over the network. A successful exploitation of this vulnerability may lead to code execution outside ... Read more

    Affected Products :
    • Published: Nov. 12, 2024
    • Modified: Nov. 12, 2024
  • 5.3

    MEDIUM
    CVE-2024-39281

    The command ctl_persistent_reserve_out allows the caller to specify an arbitrary size which will be passed to the kernel's memory allocator.... Read more

    Affected Products : freebsd
    • Published: Nov. 12, 2024
    • Modified: Jan. 10, 2025
  • 7.8

    HIGH
    CVE-2024-37365

    A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save projects within the public directory allowing anyone with local access to modify and/or delete files. Additionally, a malicious user could potenti... Read more

    Affected Products : factorytalk_view
    • Published: Nov. 12, 2024
    • Modified: Nov. 12, 2024
  • 5.2

    MEDIUM
    CVE-2024-33660

    An exploit is possible where an actor with physical access can manipulate SPI flash without being detected.... Read more

    Affected Products : aptio_v
    • Published: Nov. 12, 2024
    • Modified: Nov. 12, 2024
  • 4.4

    MEDIUM
    CVE-2024-33658

    APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bounds of a Memory Buffer by local. Successful exploitation of this vulnerability may lead to privilege escalation and potentially arbitra... Read more

    Affected Products : aptio_v
    • Published: Nov. 12, 2024
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2024-2315

    APTIOV contains a vulnerability in BIOS where may cause Improper Access Control by a local attacker. Successful exploitation of this vulnerability may lead to unexpected SPI flash modifications and BIOS boot kit launches, also impacting the availability.... Read more

    Affected Products : aptio_v
    • Published: Nov. 12, 2024
    • Modified: Nov. 21, 2024
  • 5.1

    MEDIUM
    CVE-2024-11130

    A vulnerability was found in ZZCMS up to 2023. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/msg.php. The manipulation of the argument keyword leads to cross site scripting. The attack may be lau... Read more

    Affected Products : zzcms
    • Published: Nov. 12, 2024
    • Modified: Nov. 15, 2024
  • 8.8

    HIGH
    CVE-2024-11127

    A vulnerability was found in code-projects Job Recruitment up to 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file admin.php. The manipulation of the argument userid leads to sql injection. The a... Read more

    Affected Products : job_recruitment
    • Published: Nov. 12, 2024
    • Modified: Nov. 15, 2024
  • 3.1

    LOW
    CVE-2024-11126

    A vulnerability was found in Digistar AG-30 Plus 2.6b. It has been classified as problematic. Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of excessive authentication attempts. The complexity ... Read more

    Affected Products :
    • Published: Nov. 12, 2024
    • Modified: Nov. 12, 2024
  • 6.9

    MEDIUM
    CVE-2024-11125

    A vulnerability was found in GetSimpleCMS 3.3.16 and classified as problematic. This issue affects some unknown processing of the file /admin/profile.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The expl... Read more

    Affected Products : getsimplecms
    • Published: Nov. 12, 2024
    • Modified: Nov. 15, 2024
Showing 20 of 291782 Results