VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,030 CVE recordsPage 996 of 1202 · EPSS data 2026.08.08
ReviewHigh
CVE-2024-45331

Fortinet FortiAnalyzer Cloud, FortiManager, FortiAnalyzer

A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.2, FortiAnalyzer Cloud 7.2.1 through 7.2.6, FortiAnalyzer Cloud 7.0 all versions, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions allows attacker to escalate privilege via specific shell commands

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-22916

re11s firmware, re11s

RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-22912

re11s firmware, re11s

RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-22907

re11s firmware, re11s

RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-22906

re11s firmware, re11s

RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-22905

re11s firmware, re11s

RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-22904

re11s firmware, re11s

RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.

The CVSS severity warrants an early asset and exposure review.
CISA KEVHigh
CVE-2024-57728

SimpleHelp

SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVHigh
CVE-2024-57727

simplehelp

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVCritical
CVE-2024-57726

SimpleHelp

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
PriorityCritical
CVE-2024-12084

Red Hat Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.

FIRST EPSS indicates an elevated probability of exploitation.
ReviewHigh
CVE-2024-57899

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix mbss changed flags corruption on 32 bit systems On 32-bit systems, the size of an unsigned long is 4 bytes, while a u64 is 8 bytes. Therefore, when using or_each_set_bit(bit, &bits, sizeof(changed) * BITS_PER_BYTE), the code is incorrectly searching for a bit in a 32-bit variable that is expected to be 64 bits in size, leading to incorrect bit finding. Solution: Ensure that the size of the bits variable is correctly adjusted for each architecture. Call Trace: ? show_regs+0x54/0x58 ? __warn+0x6b/0xd4 ? ie...

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2024-57483

i24 firmware, i24

Tenda i24 V2.0.0.5 is vulnerable to Buffer Overflow in the addWifiMacFilter function.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2024-57473

n12 firmware, n12

H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address editing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2024-42911

the affected product

ECOVACS Robotics Deebot T20 OMNI and T20e OMNI before 1.24.0 was discovered to contain a WiFi Remote Code Execution vulnerability.

The CVSS severity warrants an early asset and exposure review.