Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2024-24919
Known exploited
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
CVSS Score
8.6
EPSS Score
0.943
Published
2024-05-28
CVE-2024-5274
Known exploited
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS Score
9.6
EPSS Score
0.038
Published
2024-05-28
CVE-2024-4978
Known exploited
Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.
CVSS Score
8.7
EPSS Score
0.141
Published
2024-05-23
CVE-2024-4947
Known exploited
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS Score
9.6
EPSS Score
0.004
Published
2024-05-15
CVE-2024-30051
Known exploited
Windows DWM Core Library Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.435
Published
2024-05-14
CVE-2024-30040
Known exploited
Windows MSHTML Platform Security Feature Bypass Vulnerability
CVSS Score
8.8
EPSS Score
0.235
Published
2024-05-14
CVE-2024-4761
Known exploited
Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
CVSS Score
8.8
EPSS Score
0.025
Published
2024-05-14
CVE-2024-4671
Known exploited
Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVSS Score
9.6
EPSS Score
0.002
Published
2024-05-14
CVE-2024-32113
Known exploited
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.
CVSS Score
9.8
EPSS Score
0.94
Published
2024-05-08
CVE-2023-50224
Known exploited
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. . Was ZDI-CAN-19899.
CVSS Score
6.5
EPSS Score
0.015
Published
2024-05-03


Contact Us

Shodan ® - All rights reserved