VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,873 CVE recordsPage 1060 of 1192 · EPSS data 2026.08.07
CISA KEVHigh
CVE-2024-21412

Microsoft Windows

CVE-2024-21412 affects Microsoft Windows. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVCritical
CVE-2024-21410

Microsoft Exchange Server

CVE-2024-21410 affects Microsoft Exchange Server. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVHigh
CVE-2024-21351

Microsoft Windows

CVE-2024-21351 affects Microsoft Windows. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVHigh
CVE-2024-21338

Microsoft Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation)

CVE-2024-21338 affects Microsoft Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation). Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewHigh
CVE-2024-21490

angular, org.webjars.bower:angular, org.webjars.npm:angular

This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service. **Note:** This package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2024-25675

misp

An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related to app/Controller/JobsController.php and app/View/Events/export.ctp.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2024-25674

misp

An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.

The CVSS severity warrants an early asset and exposure review.
CISA KEVCritical
CVE-2024-21762

Fortinet FortiProxy, FortiOS, fortiproxy

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewCritical
CVE-2024-24321

dir-816 firmware, dir-816

An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.

The CVSS severity warrants an early asset and exposure review.
PriorityCritical
CVE-2023-46359

cph2 echarge firmware, cph2 echarge

An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted arguments passed to the connectivity check feature.

FIRST EPSS indicates an elevated probability of exploitation.
ReviewCritical
CVE-2024-24398

dashboards.php

Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2024-22903

vinchin backup and recovery

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.

The CVSS severity warrants an early asset and exposure review.