VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,030 CVE recordsPage 1015 of 1202 · EPSS data 2026.08.07
ReviewCritical
CVE-2024-48778

ridelink_firmware

An issue in GIANT MANUFACTURING CO., LTD RideLink (tw.giant.ridelink) 2.0.7 allows a remote attacker to obtain sensitive information via the firmware update process.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2024-48777

smartplus_firmware

LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2024-48776

home_firmware

An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2024-48775

ezset_firmware

An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2024-48774

vida

An issue in Fermax Asia Pacific Pte Ltd com.fermax.vida 2.4.6 allows a remote attacker to obtain sensitve information via the firmware update process.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2024-48773

morepro_firmware

An issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update process

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2024-48771

almando_play_firmware

An issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to obtain sensitive information via the firmware update process

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2024-48770

com.wisdomcity.zwave

An issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain sensitive information via the firmware update process.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2024-48769

burg-wchter_kg_firmware

An issue in BURG-WCHTER KG de.burgwachter.keyapp.app 4.5.0 allows a remote attacker to obtain sensitve information via the firmware update process.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2024-48768

almando_control_firmware

An issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to obtain sensitive information via the firmware update process

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2024-46532

openhis

SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the PayController.class.php component.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2024-46088

entersoft_customer_resource_management

An arbitrary file upload vulnerability in the ProductAction.entphone interface of Zhejiang University Entersoft Customer Resource Management System v2002 to v2024 allows attackers to execute arbitrary code via uploading a crafted file.

The CVSS severity warrants an early asset and exposure review.
CISA KEVCritical
CVE-2024-9465

Palo Alto Networks Expedition

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVCritical
CVE-2024-9463

Palo Alto Networks Expedition

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewHigh
CVE-2024-46307

sparkshop

A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.

The CVSS severity warrants an early asset and exposure review.