Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2025-23006
Known exploited
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.
CVSS Score
9.8
EPSS Score
0.234
Published
2025-01-23
CVE-2025-23209
Known exploited
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security key is affected. This vulnerability has been patched in Craft 5.5.8 and 4.13.8. Users who cannot update to a patched version, should rotate their security keys and ensure their privacy to help migitgate the issue.
CVSS Score
8.0
EPSS Score
0.218
Published
2025-01-18
CVE-2024-57726
Known exploited
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
CVSS Score
9.9
EPSS Score
0.666
Published
2025-01-15
CVE-2024-57727
Known exploited
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.
CVSS Score
7.5
EPSS Score
0.952
Published
2025-01-15
CVE-2024-57728
Known exploited
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
CVSS Score
7.2
EPSS Score
0.07
Published
2025-01-15
CVE-2025-21333
Known exploited
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.1
Published
2025-01-14
CVE-2025-21334
Known exploited
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.016
Published
2025-01-14
CVE-2025-21335
Known exploited
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.014
Published
2025-01-14
CVE-2024-13159
Known exploited
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
CVSS Score
9.8
EPSS Score
1.0
Published
2025-01-14
CVE-2024-13160
Known exploited
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
CVSS Score
9.8
EPSS Score
0.912
Published
2025-01-14


Contact Us

Shodan ® - All rights reserved