Critical
|
25 Feb 2025 |
25 Feb 2025 |
CPAI-2024-1314
|
|
CVE-2024-46045 CVE-2024-8225 CVE-2024-8227
|
Tenda Multiple Products Stack-Based Buffer Overflow (CVE-2024-46045; CVE-2024-8225; CVE-2024-8227)
|
High
|
24 Feb 2025 |
24 Feb 2025 |
CPAI-2025-0053
|
|
CVE-2025-0110
|
Palo Alto Networks PAN-OS OpenConfig Plugin Command Injection (CVE-2025-0110)
|
Critical
|
24 Feb 2025 |
24 Feb 2025 |
CPAI-2024-1421
|
|
CVE-2024-29974
|
Zyxel NAS326 firmware Remote Code Execution (CVE-2024-29974)
|
Medium
|
24 Feb 2025 |
24 Feb 2025 |
CPAI-2024-1419
|
|
CVE-2024-29976
|
Zyxel NAS326 firmware Information Disclosure (CVE-2024-29976)
|
High
|
24 Feb 2025 |
24 Feb 2025 |
CPAI-2025-0047
|
|
CVE-2025-24893
|
XWiki.org XWiki Code Injection (CVE-2025-24893)
|
High
|
13 Feb 2025 |
24 Feb 2025 |
CPAI-2025-0038
|
|
CVE-2025-0108
|
Palo Alto Networks PAN-OS Authentication Bypass (CVE-2025-0108)
|
High
|
23 Feb 2025 |
23 Feb 2025 |
CPAI-2025-0045
|
|
CVE-2025-1340
|
TOTOLINK X18 Stack Overflow (CVE-2025-1340)
|
Critical
|
23 Feb 2025 |
23 Feb 2025 |
CPAI-2024-1303
|
|
CVE-2024-52544
|
Lorex 2K Indoor Wi-Fi Security Camera Buffer Overflow (CVE-2024-52544)
|
Critical
|
23 Feb 2025 |
23 Feb 2025 |
CPAI-2024-1403
|
|
CVE-2024-34200 CVE-2024-34201 CVE-2024-34203 CVE-2024-34207 CVE-2024-34209 CVE-2024-34212 CVE-2024-34213 CVE-2024-34215
|
TOTOLINK CP450 Buffer Overflow (CVE-2024-34200; CVE-2024-34201; CVE-2024-34203; CVE-2024-34207; CVE-2024-34209; CVE-2024-34212; CVE-2024-34213; CVE-2024-34215)
|
High
|
23 Feb 2025 |
23 Feb 2025 |
CPAI-2023-2006
|
|
CVE-2023-51146 CVE-2023-51147
|
TRENDnet TEW-821DAP Buffer Overflow (CVE-2023-51146; CVE-2023-51147)
|
High
|
19 Feb 2025 |
23 Feb 2025 |
CPAI-2024-1401
|
|
CVE-2024-40890
|
Zyxel Multiple Products Command Injection (CVE-2024-40890)
|
High
|
30 Jan 2025 |
23 Feb 2025 |
CPAI-2025-0020
|
|
CVE-2025-0105
|
Palo Alto Networks Expedition Arbitrary File Deletion (CVE-2025-0105)
|
Critical
|
20 Feb 2025 |
20 Feb 2025 |
CPAI-2024-1410
|
|
CVE-2024-10811 CVE-2024-13159 CVE-2024-13160 CVE-2024-13161
|
Ivanti Endpoint Manager Path Traversal (CVE-2024-10811; CVE-2024-13159; CVE-2024-13160; CVE-2024-13161)
|
Critical
|
20 Feb 2025 |
20 Feb 2025 |
CPAI-2024-1404
|
|
CVE-2024-34204 CVE-2024-34206 CVE-2024-34210
|
TOTOLINK CP450 Command Injection (CVE-2024-34204; CVE-2024-34206; CVE-2024-34210)
|
High
|
20 Feb 2025 |
20 Feb 2025 |
CPAI-2021-2296
|
|
CVE-2021-27030
|
Autodesk FBX Review Directory Traversal (CVE-2021-27030)
|
Medium
|
9 Feb 2025 |
20 Feb 2025 |
CPAI-2024-1360
|
|
CVE-2024-39288 CVE-2024-39359
|
Wavlink AC3000 Buffer Overflow (CVE-2024-39288; CVE-2024-39359)
|
Critical
|
19 Feb 2025 |
19 Feb 2025 |
CPAI-2025-0043
|
|
CVE-2014-0130 CVE-2015-3035 CVE-2016-4523 CVE-2019-20085 CVE-2020-5410 CVE-2023-2825 CVE-2023-32315 CVE-2023-34843 CVE-2023-34990 CVE-2023-35843 CVE-2023-35844 CVE-2023-37607 CVE-2023-41266 CVE-2024-57727
|
Web Servers Directory Traversal (CVE-2014-0130; CVE-2015-3035; CVE-2016-4523; CVE-2019-20085; CVE-2020-5410; CVE-2023-2825; CVE-2023-32315; CVE-2023-34843; CVE-2023-34990; CVE-2023-35843; CVE-2023-35844; CVE-2023-37607; CVE-2023-41266; CVE-2024-57727)
|
Critical
|
2 Feb 2025 |
19 Feb 2025 |
CPAI-2024-1351
|
|
CVE-2024-53704
|
SonicWall SonicOS Authentication Bypass (CVE-2024-53704)
|
High
|
18 Feb 2025 |
18 Feb 2025 |
CPAI-2024-1394
|
|
CVE-2024-37569 CVE-2024-37570
|
Mitel 6869i Command Injection (CVE-2024-37569; CVE-2024-37570)
|
High
|
18 Feb 2025 |
18 Feb 2025 |
CPAI-2024-1388
|
|
CVE-2024-48456
|
Netis Multiple Products Remote Code Execution (CVE-2024-48456)
|
High
|
18 Feb 2025 |
18 Feb 2025 |
CPAI-2024-1372
|
|
CVE-2024-57357
|
TP-Link TL-WPA 8630 Command Injection (CVE-2024-57357)
|
Critical
|
17 Feb 2025 |
17 Feb 2025 |
CPAI-2025-0042
|
|
CVE-2025-25064
|
Zimbra Collaboration SQL Injection (CVE-2025-25064)
|
High
|
17 Feb 2025 |
17 Feb 2025 |
CPAI-2025-0041
|
|
CVE-2025-1094
|
PostgreSQL SQL Injection (CVE-2025-1094)
|
Critical
|
17 Feb 2025 |
17 Feb 2025 |
CPAI-2024-1402
|
|
CVE-2024-12356
|
BeyondTrust Multiple Products Command Injection (CVE-2024-12356)
|
High
|
17 Feb 2025 |
17 Feb 2025 |
CPAI-2025-0036
|
|
CVE-2025-24367
|
Cacti Group Cacti CRLF Injection (CVE-2025-24367)
|
High
|
17 Feb 2025 |
17 Feb 2025 |
CPAI-2024-1384
|
|
CVE-2024-23333
|
LDAP Account Manager Remote Code Execution (CVE-2024-23333)
|
High
|
16 Feb 2025 |
16 Feb 2025 |
CPAI-2024-1385
|
|
CVE-2024-48455 CVE-2024-48457
|
Netis Multiple Products Authentication Bypass (CVE-2024-48455; CVE-2024-48457)
|
High
|
16 Feb 2025 |
16 Feb 2025 |
CPAI-2025-0031
|
|
CVE-2025-21385
|
Microsoft Purview Server-Side Request Forgery (CVE-2025-21385)
|
Medium
|
16 Feb 2025 |
16 Feb 2025 |
CPAI-2024-1377
|
|
CVE-2024-54502
|
Apple Multiple Products Use After Free (CVE-2024-54502)
|
Critical
|
16 Feb 2025 |
16 Feb 2025 |
CPAI-2023-1999
|
|
CVE-2023-45249
|
Acronis Cyber Infrastructure Authentication Bypass (CVE-2023-45249)
|
Critical
|
13 Feb 2025 |
13 Feb 2025 |
CPAI-2024-1393
|
|
CVE-2024-9916
|
HuangDou UTCMS Command Injection (CVE-2024-9916)
|
Critical
|
13 Feb 2025 |
13 Feb 2025 |
CPAI-2024-1386
|
|
CVE-2024-39363
|
Wavlink AC3000 Cross-Site Scripting (CVE-2024-39363)
|
Medium
|
13 Feb 2025 |
13 Feb 2025 |
CPAI-2025-0033
|
|
CVE-2025-25181
|
Advantive VeraCore SQL Injection (CVE-2025-25181)
|
High
|
13 Feb 2025 |
13 Feb 2025 |
CPAI-2024-1383
|
|
CVE-2024-45518
|
Zimbra Collaboration Server-Side Request Forgery (CVE-2024-45518)
|
Critical
|
13 Feb 2025 |
13 Feb 2025 |
CPAI-2024-1382
|
|
CVE-2024-57968
|
Advantive VeraCore Arbitrary File Upload (CVE-2024-57968)
|
Medium
|
13 Feb 2025 |
13 Feb 2025 |
CPAI-2024-1367
|
|
CVE-2024-55947
|
Gogs Path Traversal (CVE-2024-55947)
|
High
|
13 Feb 2025 |
13 Feb 2025 |
CPAI-2024-1366
|
|
CVE-2024-47008
|
Ivanti Avalanche Server-Side Request Forgery (CVE-2024-47008)
|
Medium
|
13 Feb 2025 |
13 Feb 2025 |
CPAI-2018-2894
|
|
CVE-2018-11552
|
NCH AXON PBX Cross-Site Scripting (CVE-2018-11552)
|
High
|
30 Jan 2025 |
13 Feb 2025 |
CPAI-2024-1345
|
|
CVE-2024-41710
|
Mitel Multiple Products Command Injection (CVE-2024-41710)
|
Critical
|
12 Feb 2025 |
12 Feb 2025 |
CPAI-2025-0035
|
Microsoft CVE-2025-21376
|
CVE-2025-21376
|
Microsoft Windows LDAP Remote Code Execution (CVE-2025-21376)
|
Critical
|
12 Feb 2025 |
12 Feb 2025 |
CPAI-2023-1998
|
|
CVE-2023-49403 CVE-2023-49999
|
Tenda W30E Command Injection (CVE-2023-49403; CVE-2023-49999)
|
Medium
|
12 Feb 2025 |
12 Feb 2025 |
CPAI-2023-1995
|
|
CVE-2023-6065
|
WordPress Quttera Web Malware Scanner Plugin Information Disclosure (CVE-2023-6065)
|
Medium
|
11 Feb 2025 |
11 Feb 2025 |
CPAI-2025-0032
|
Microsoft CVE-2025-21377
|
CVE-2025-21377
|
Microsoft Windows NTLM Information Disclosure (CVE-2025-21377)
|
High
|
11 Feb 2025 |
11 Feb 2025 |
CPAI-2025-0030
|
Microsoft CVE-2025-21400
|
CVE-2025-21400
|
Microsoft SharePoint Server Remote Code Execution (CVE-2025-21400)
|
High
|
10 Feb 2025 |
10 Feb 2025 |
CPAI-2024-1355
|
|
CVE-2024-55417
|
PHP Voyager Package Arbitrary File Upload (CVE-2024-55417)
|
High
|
10 Feb 2025 |
10 Feb 2025 |
CPAI-2024-1302
|
|
CVE-2024-0778
|
Uniview ISC 2500-S Command Injection (CVE-2024-0778)
|
High
|
9 Feb 2025 |
9 Feb 2025 |
CPAI-2024-1363
|
|
CVE-2024-38653
|
Ivanti Avalanche XML External Entity Injection (CVE-2024-38653)
|
Medium
|
9 Feb 2025 |
9 Feb 2025 |
CPAI-2024-1361
|
|
CVE-2024-45607
|
Secreto31126 Whatsapp-Api-js Improper Access Control (CVE-2024-45607)
|
High
|
9 Feb 2025 |
9 Feb 2025 |
CPAI-2024-1353
|
|
CVE-2024-55416
|
PHP Voyager Package Cross-Site Scripting (CVE-2024-55416)
|
High
|
9 Feb 2025 |
9 Feb 2025 |
CPAI-2024-1352
|
|
CVE-2024-55415
|
PHP Voyager Package Path Traversal (CVE-2024-55415)
|