Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2024-23225
Known exploited
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.
CVSS Score
7.8
EPSS Score
0.0
Published
2024-03-05
CVE-2024-23296
Known exploited
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 17.4 and iPadOS 17.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.
CVSS Score
7.8
EPSS Score
0.001
Published
2024-03-05
CVE-2024-27198
Known exploited
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
CVSS Score
9.8
EPSS Score
0.946
Published
2024-03-04
CVE-2024-1212
Known exploited
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
CVSS Score
10.0
EPSS Score
0.944
Published
2024-02-21
CVE-2024-1709
Known exploited
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.
CVSS Score
10.0
EPSS Score
0.944
Published
2024-02-21
CVE-2024-20953
Known exploited
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVSS Score
8.8
EPSS Score
0.765
Published
2024-02-17
CVE-2024-23113
Known exploited
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.
CVSS Score
9.8
EPSS Score
0.456
Published
2024-02-15
CVE-2024-21413
Known exploited
Microsoft Outlook Remote Code Execution Vulnerability
CVSS Score
9.8
EPSS Score
0.938
Published
2024-02-13
CVE-2024-21410
Known exploited
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVSS Score
9.8
EPSS Score
0.015
Published
2024-02-13
CVE-2024-21412
Known exploited
Internet Shortcut Files Security Feature Bypass Vulnerability
CVSS Score
8.1
EPSS Score
0.938
Published
2024-02-13


Contact Us

Shodan ® - All rights reserved