NAVANEM

Documented vulnerability advisories

Every entry documented: technical breakdown, impact, mitigation and detection, with severity, CVSS and exploitation status at a glance.

124advisories
75critical
95exploited in the wild

124 advisories

Palo Alto PAN-OS, privilege escalation in management web interface
CVE-2024-9474· Nov 18, 2024high

Palo Alto PAN-OS, privilege escalation in management web interface

A privilege escalation (PE) vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges.

Palo Alto PAN-OS, authentication bypass in management web interface
CVE-2024-0012· Nov 18, 2024critical

Palo Alto PAN-OS, authentication bypass in management web interface

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions.

Windows Task Scheduler, elevation of privilege zero-day
CVE-2024-49039· Nov 12, 2024high

Windows Task Scheduler, elevation of privilege zero-day

Windows Task Scheduler Elevation of Privilege Vulnerability.

Fortinet FortiManager, missing authentication on fgfmd (FortiJump)
CVE-2024-47575· Oct 23, 2024critical

Fortinet FortiManager, missing authentication on fgfmd (FortiJump)

A missing authentication for critical function vulnerability in Fortinet FortiManager allows a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.

Microsoft Windows Update, servicing-stack rollback enables RCE on Windows 10 1507
CVE-2024-43491· Sep 10, 2024critical

Microsoft Windows Update, servicing-stack rollback enables RCE on Windows 10 1507

Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015).

Windows TCP/IP, IPv6 remote code execution (wormable)
CVE-2024-38063· Aug 13, 2024critical

Windows TCP/IP, IPv6 remote code execution (wormable)

An unauthenticated attacker could repeatedly send IPv6 packets, that include specially crafted packets, to a Windows machine which could enable remote code execution.

Windows Hyper-V, elevation of privilege zero-day
CVE-2024-38080· Jul 9, 2024high

Windows Hyper-V, elevation of privilege zero-day

Windows Hyper-V Elevation of Privilege Vulnerability. Successful exploitation could allow a malicious authenticated attacker to gain SYSTEM privileges on the host operating system.

Windows MSHTML platform, spoofing zero-day (Void Banshee)
CVE-2024-38112· Jul 9, 2024high

Windows MSHTML platform, spoofing zero-day (Void Banshee)

Windows MSHTML Platform Spoofing Vulnerability. Successful exploitation requires the attacker to send the user a malicious file, which the user must execute.

OpenSSH server (sshd), signal handler race leading to pre-auth RCE (regreSSHion)
CVE-2024-6387· Jul 1, 2024high

OpenSSH server (sshd), signal handler race leading to pre-auth RCE (regreSSHion)

A signal handler race condition was found in OpenSSH's server (sshd), where a client does not authenticate within LoginGraceTime seconds (120 by default), then sshd's SIGALRM handler is called asynchronously, but this signal handler calls various functions that are not async-signal-safe.

VMware ESXi, Active Directory integration authentication bypass (ransomware abuse)
CVE-2024-37085· Jun 25, 2024high

VMware ESXi, Active Directory integration authentication bypass (ransomware abuse)

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESX Admins' by default) after it was deleted from AD.

Veeam Backup Enterprise Manager, authentication bypass
CVE-2024-29849· May 21, 2024critical

Veeam Backup Enterprise Manager, authentication bypass

Vulnerability in Veeam Backup Enterprise Manager allows unauthenticated attackers to log in to the Veeam Backup Enterprise Manager web interface as any user.

Windows Desktop Window Manager (DWM) Core Library, elevation of privilege
CVE-2024-30051· May 14, 2024high

Windows Desktop Window Manager (DWM) Core Library, elevation of privilege

Windows DWM Core Library Elevation of Privilege Vulnerability.

Windows MSHTML, COM platform security feature bypass (zero-day)
CVE-2024-30040· May 14, 2024high

Windows MSHTML, COM platform security feature bypass (zero-day)

Windows MSHTML Platform Security Feature Bypass Vulnerability. An attacker would need to send a malicious file to the user, which they would then need to execute. An authenticated attacker who successfully exploited this vulnerability could bypass OLE mitigations in Microsoft 365 and Microsoft Office.

Palo Alto Networks PAN-OS GlobalProtect, unauthenticated command injection
CVE-2024-3400· Apr 12, 2024critical

Palo Alto Networks PAN-OS GlobalProtect, unauthenticated command injection

A command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.

XZ Utils, malicious code in liblzma backdoors sshd (supply-chain)
CVE-2024-3094· Mar 29, 2024critical

XZ Utils, malicious code in liblzma backdoors sshd (supply-chain)

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code.

Windows Error Reporting Service, elevation of privilege (Black Basta)
CVE-2024-26169· Mar 12, 2024high

Windows Error Reporting Service, elevation of privilege (Black Basta)

Windows Error Reporting Service Elevation of Privilege Vulnerability.

JetBrains TeamCity, authentication bypass via path traversal
CVE-2024-27198· Mar 4, 2024critical

JetBrains TeamCity, authentication bypass via path traversal

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible.

JetBrains TeamCity, path traversal authentication bypass on selected endpoints
CVE-2024-27199· Mar 4, 2024high

JetBrains TeamCity, path traversal authentication bypass on selected endpoints

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible.

ConnectWise ScreenConnect, path traversal in extension upload
CVE-2024-1708· Feb 19, 2024high

ConnectWise ScreenConnect, path traversal in extension upload

ConnectWise ScreenConnect 23.9.7 and prior is affected by a path traversal vulnerability allowing access to or modification of items outside of the intended directory structure.

ConnectWise ScreenConnect, auth bypass via path normalization (SlashAndGrab)
CVE-2024-1709· Feb 19, 2024critical

ConnectWise ScreenConnect, auth bypass via path normalization (SlashAndGrab)

ConnectWise ScreenConnect 23.9.7 and prior is affected by an authentication bypass using an alternate path or channel vulnerability that allows access to administrative functions.

show