High
|
20 Jan 2025 |
20 Jan 2025 |
CPAI-2024-1230
|
|
CVE-2024-47007 CVE-2024-50317 CVE-2024-50318 CVE-2024-50319
|
Ivanti Avalanche Denial of Service (CVE-2024-47007; CVE-2024-50317; CVE-2024-50318; CVE-2024-50319)
|
High
|
20 Jan 2025 |
20 Jan 2025 |
CPAI-2024-1238
|
|
CVE-2024-31621
|
Flowise Authentication Bypass (CVE-2024-31621)
|
Critical
|
20 Jan 2025 |
20 Jan 2025 |
CPAI-2024-1239
|
|
CVE-2024-3552
|
WordPress SalePHPscripts Web Directory Free Plugin SQL Injection (CVE-2024-3552)
|
High
|
20 Jan 2025 |
20 Jan 2025 |
CPAI-2023-1462
|
|
CVE-2023-51572
|
Voltronic Power ViewPower Pro Command Injection (CVE-2023-51572)
|
High
|
20 Jan 2025 |
20 Jan 2025 |
CPAI-2023-1501
|
|
CVE-2023-50223
|
Inductive Automation Ignition Insecure Deserialization (CVE-2023-50223)
|
Medium
|
20 Jan 2025 |
20 Jan 2025 |
CPAI-2024-1121
|
|
CVE-2024-24942
|
JetBrains TeamCity Directory Traversal (CVE-2024-24942)
|
Critical
|
20 Jan 2025 |
20 Jan 2025 |
CPAI-2024-1246
|
|
CVE-2024-9932
|
WordPress Wux Blog Editor Plugin Arbitrary File Upload (CVE-2024-9932)
|
High
|
20 Jan 2025 |
20 Jan 2025 |
CPAI-2007-0499
|
|
CVE-2007-3175
|
W2B Online Banking SQL Injection (CVE-2007-3175)
|
Critical
|
20 Jan 2025 |
20 Jan 2025 |
CPAI-2023-1985
|
|
CVE-2023-31446
|
Cassia Network Gateway Command Injection (CVE-2023-31446)
|
High
|
19 Jan 2025 |
19 Jan 2025 |
CPAI-2021-2281
|
|
CVE-2021-33959
|
Plex Media Server Distributed Denial of Service (CVE-2021-33959)
|
High
|
17 Jan 2025 |
17 Jan 2025 |
CPAI-2024-1224
|
|
CVE-2024-49113
|
Microsoft Windows LDAP Denial of Service (CVE-2024-49113)
|
High
|
16 Jan 2025 |
16 Jan 2025 |
CPAI-2024-1250
|
|
CVE-2024-43464
|
Microsoft SharePoint Server Remote Code Execution (CVE-2024-43464)
|
High
|
16 Jan 2025 |
16 Jan 2025 |
CPAI-2024-1243
|
|
CVE-2024-25723
|
ZenML Server Privilege Escalation (CVE-2024-25723)
|
Medium
|
16 Jan 2025 |
16 Jan 2025 |
CPAI-2024-1242
|
|
CVE-2024-0881
|
WordPress Combo Blocks Plugin Authentication Bypass (CVE-2024-0881)
|
Critical
|
16 Jan 2025 |
16 Jan 2025 |
CPAI-2023-1983
|
|
CVE-2023-4521
|
WordPress Moove Import XML and RSS Feeds Plugin Remote Code Execution (CVE-2023-4521)
|
Critical
|
16 Jan 2025 |
16 Jan 2025 |
CPAI-2024-1231
|
|
CVE-2024-8856
|
WordPress Time Capsule Plugin Remote Code Execution (CVE-2024-8856)
|
High
|
16 Jan 2025 |
16 Jan 2025 |
CPAI-2024-1227
|
|
CVE-2024-21182
|
Oracle WebLogic Server Remote Code Execution (CVE-2024-21182)
|
Medium
|
16 Jan 2025 |
16 Jan 2025 |
CPAI-2016-1270
|
|
CVE-2016-8652
|
Dovecot Denial of Service (CVE-2016-8652)
|
Critical
|
15 Jan 2025 |
15 Jan 2025 |
CPAI-2023-1979
|
|
CVE-2023-2227
|
Modoboa Information Disclosure (CVE-2023-2227)
|
High
|
15 Jan 2025 |
15 Jan 2025 |
CPAI-2024-1241
|
|
CVE-2024-54819
|
I Librarian Server-Side Request Forgery (CVE-2024-54819)
|
High
|
15 Jan 2025 |
15 Jan 2025 |
CPAI-2024-1235
|
|
CVE-2024-2805 CVE-2024-2806 CVE-2024-2807 CVE-2024-2808 CVE-2024-2809 CVE-2024-2810 CVE-2024-2811 CVE-2024-2813 CVE-2024-2814
|
Tenda AC15 Buffer Overflow (CVE-2024-2805; CVE-2024-2806; CVE-2024-2807; CVE-2024-2808; CVE-2024-2809; CVE-2024-2810; CVE-2024-2811; CVE-2024-2813; CVE-2024-2814)
|
Medium
|
15 Jan 2025 |
15 Jan 2025 |
CPAI-2024-1233
|
|
CVE-2024-12343
|
TP-Link VN020 F3v Buffer Overflow (CVE-2024-12343)
|
Medium
|
15 Jan 2025 |
15 Jan 2025 |
CPAI-2021-2280
|
|
CVE-2021-24202 CVE-2021-24203
|
WordPress Elementor Website Builder Plugin Cross-Site Scripting (CVE-2021-24202; CVE-2021-24203)
|
High
|
15 Jan 2025 |
15 Jan 2025 |
CPAI-2024-1102
|
|
CVE-2024-10387
|
Rockwell Automation ThinManager ThinServer Out-Of-Bounds Read (CVE-2024-10387)
|
Medium
|
15 Jan 2025 |
15 Jan 2025 |
CPAI-2024-1081
|
|
CVE-2024-10386
|
Rockwell Automation ThinManager Authentication Bypass (CVE-2024-10386)
|
High
|
14 Jan 2025 |
14 Jan 2025 |
CPAI-2025-0003
|
Microsoft CVE-2025-21309
|
CVE-2025-21309
|
Microsoft Windows Remote Desktop Services Remote Code Execution (CVE-2025-21309)
|
Critical
|
13 Jan 2025 |
13 Jan 2025 |
CPAI-2025-0002
|
|
CVE-2025-0282
|
Ivanti Buffer Overflow (CVE-2025-0282)
|
Medium
|
13 Jan 2025 |
13 Jan 2025 |
CPAI-2024-1244
|
|
CVE-2024-43364
|
Cacti Cross-Site Scripting (CVE-2024-43364)
|
High
|
13 Jan 2025 |
13 Jan 2025 |
CPAI-2024-1234
|
|
CVE-2024-13129
|
Roxy-WI Command Injection (CVE-2024-13129)
|
Critical
|
13 Jan 2025 |
13 Jan 2025 |
CPAI-2024-1226
|
|
CVE-2024-10456
|
Delta Electronics InfraSuite Device Master Insecure Deserialization (CVE-2024-10456)
|
Medium
|
1 Jan 2025 |
12 Jan 2025 |
CPAI-2024-1188
|
|
CVE-2024-5458
|
PHP Authentication Bypass (CVE-2024-5458)
|
Medium
|
12 Jan 2025 |
12 Jan 2025 |
CPAI-2022-2161
|
|
CVE-2022-2856
|
Google Chrome Open Redirect (CVE-2022-2856)
|
Medium
|
12 Jan 2025 |
12 Jan 2025 |
CPAI-2024-1221
|
|
CVE-2024-47855
|
Jenkins Denial of Service (CVE-2024-47855)
|
High
|
12 Jan 2025 |
12 Jan 2025 |
CPAI-2024-1229
|
|
CVE-2024-34779
|
Ivanti Endpoint Manager SQL Injection (CVE-2024-34779)
|
High
|
12 Jan 2025 |
12 Jan 2025 |
CPAI-2024-1237
|
|
CVE-2024-32848
|
Ivanti Endpoint Manager SQL Injection (CVE-2024-32848)
|
High
|
12 Jan 2025 |
12 Jan 2025 |
CPAI-2024-1245
|
|
CVE-2024-12105
|
Progress WhatsUp Gold Path Traversal (CVE-2024-12105)
|
Medium
|
12 Jan 2025 |
12 Jan 2025 |
CPAI-2024-1170
|
|
CVE-2024-54003
|
Jenkins Simple Queue Plugin Cross-Site Scripting (CVE-2024-54003)
|
Medium
|
12 Jan 2025 |
12 Jan 2025 |
CPAI-2024-1228
|
|
CVE-2024-2340
|
Avada Information Disclosure (CVE-2024-2340)
|
High
|
12 Jan 2025 |
12 Jan 2025 |
CPAI-2023-1981
|
|
CVE-2023-20888
|
VMware VRealize Network Insight Insecure Deserialization (CVE-2023-20888)
|
High
|
12 Jan 2025 |
12 Jan 2025 |
CPAI-2023-1984
|
|
CVE-2023-5003
|
Active Directory / LDAP Integration WordPress Plugin Information Disclosure (CVE-2023-5003)
|
Critical
|
9 Jan 2025 |
9 Jan 2025 |
CPAI-2023-1982
|
|
CVE-2023-34563
|
NETGEAR R6250 Buffer Overflow (CVE-2023-34563)
|
High
|
7 Jan 2025 |
7 Jan 2025 |
CPAI-2024-1182
|
|
|
Microsoft SQL Server Management Studio Brute Force Login Attempt
|
High
|
7 Jan 2025 |
7 Jan 2025 |
CPAI-2024-1225
|
|
CVE-2024-9122
|
Google Chrome V8 Type Confusion (CVE-2024-9122)
|
High
|
7 Jan 2025 |
7 Jan 2025 |
CPAI-2017-1948
|
|
CVE-2017-16651
|
RoundCube Webmail Local File Inclusion (CVE-2017-16651)
|
Critical
|
7 Jan 2025 |
7 Jan 2025 |
CPAI-2024-1200
|
|
CVE-2024-40725
|
HTTP Requests Smuggling (CVE-2024-40725)
|
High
|
6 Jan 2025 |
6 Jan 2025 |
CPAI-2024-1218
|
|
CVE-2024-12987
|
DrayTek Vigor Command Injection (CVE-2024-12987)
|
High
|
6 Jan 2025 |
6 Jan 2025 |
CPAI-2024-0848
|
|
CVE-2024-8124
|
GitLab Denial-of-Service (CVE-2024-8124)
|
Critical
|
6 Jan 2025 |
6 Jan 2025 |
CPAI-2018-2875
|
|
CVE-2018-17532
|
Teltonika RUT9XX Command Injection (CVE-2018-17532)
|
High
|
5 Jan 2025 |
5 Jan 2025 |
CPAI-2018-2871
|
|
CVE-2018-7777
|
Schneider Electric U.motion Builder Command Injection (CVE-2018-7777)
|
Medium
|
5 Jan 2025 |
5 Jan 2025 |
CPAI-2024-1214
|
|
CVE-2024-50320
|
Ivanti Avalanche Denial of Service (CVE-2024-50320)
|