CVE Tracker
Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.
1,539
Total CVEs
1,539
CISA KEV
1539
Critical & High
Mar 9, 2026
Last KEV Update
| CVE ID | Severity | Vendor | Description | Published | KEV |
|---|---|---|---|---|---|
| CVE-2024-3393 | High | Palo Alto NetworksPAN-OS | Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode. | Dec 30, 2024 | KEV |
| CVE-2021-44207 | High | Acclaim SystemsUSAHERDS | Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be obtained via a separate vulnerability or other channel. | Dec 23, 2024 | KEV |
| CVE-2024-12356 | High | BeyondTrustPrivileged Remote Access (PRA) and Remote Support (RS) | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user. | Dec 19, 2024 | KEV |
| CVE-2021-40407 | High | ReolinkRLC-410W IP Camera | Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality. | Dec 18, 2024 | KEV |
| CVE-2019-11001 | High | ReolinkMultiple IP Cameras | Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root. | Dec 18, 2024 | KEV |
| CVE-2022-23227 | High | NUUONVRmini2 Devices | NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users. | Dec 18, 2024 | KEV |
| CVE-2018-14933 | High | NUUONVRmini Devices | NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command. | Dec 18, 2024 | KEV |
| CVE-2024-55956 | High | CleoMultiple Products | Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory. | Dec 17, 2024 | KEV |
| CVE-2024-35250 | High | MicrosoftWindows | Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges. | Dec 16, 2024 | KEV |
| CVE-2024-20767 | High | AdobeColdFusion | Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel. | Dec 16, 2024 | KEV |
| CVE-2024-50623 | High | CleoMultiple Products | Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges. | Dec 13, 2024 | KEV |
| CVE-2024-49138 | High | MicrosoftWindows | Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges. | Dec 10, 2024 | KEV |
| CVE-2024-51378 | High | CyberPersonsCyberPanel | CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property. | Dec 4, 2024 | KEV |
| CVE-2024-11667 | High | ZyxelMultiple Firewalls | Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL. | Dec 3, 2024 | KEV |
| CVE-2024-11680 | High | ProjectSendProjectSend | ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript. | Dec 3, 2024 | KEV |
| CVE-2023-45727 | High | North GridProself | North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated attacker to conduct an XXE attack. | Dec 3, 2024 | KEV |
| CVE-2023-28461 | High | Array Networks AG/vxAG ArrayOS | Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway. | Nov 25, 2024 | KEV |
| CVE-2024-21287 | High | OracleAgile Product Lifecycle Management (PLM) | Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this vulnerability may result in unauthenticated file disclosure. | Nov 21, 2024 | KEV |
| CVE-2024-44309 | High | AppleMultiple Products | Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to a cross-site scripting (XSS) attack. | Nov 21, 2024 | KEV |
| CVE-2024-44308 | High | AppleMultiple Products | Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to arbitrary code execution. | Nov 21, 2024 | KEV |