CVE-2024-12686
BeyondTrust · Privileged Remote Access (PRA) and Remote Support (RS)
Added Jan 13, 2025
Security Bulletins
Active threat advisories and known exploited vulnerabilities.
Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jun 12, 2026.
Critical
Critical
CVE-2025-0282
Ivanti · Connect Secure, Policy Secure, and ZTA Gateways
Added Jan 8, 2025
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
Critical
CVE-2020-2883
Oracle · WebLogic Server
Added Jan 7, 2025
Oracle WebLogic Server Unspecified Vulnerability
Critical
CVE-2024-55550
Mitel · MiCollab
Added Jan 7, 2025
Mitel MiCollab Path Traversal Vulnerability
Critical
CVE-2024-41713
Mitel · MiCollab
Added Jan 7, 2025
Mitel MiCollab Path Traversal Vulnerability
Critical
CVE-2024-3393
Palo Alto Networks · PAN-OS
Added Dec 30, 2024
Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability
Critical
CVE-2021-44207
Acclaim Systems · USAHERDS
Added Dec 23, 2024
Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability
Critical
CVE-2024-12356
BeyondTrust · Privileged Remote Access (PRA) and Remote Support (RS)
Added Dec 19, 2024
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability
Critical
CVE-2021-40407
Reolink · RLC-410W IP Camera
Added Dec 18, 2024
Reolink RLC-410W IP Camera OS Command Injection Vulnerability
Critical
CVE-2019-11001
Reolink · Multiple IP Cameras
Added Dec 18, 2024
Reolink Multiple IP Cameras OS Command Injection Vulnerability
Critical
CVE-2022-23227
NUUO · NVRmini2 Devices
Added Dec 18, 2024
NUUO NVRmini2 Devices Missing Authentication Vulnerability
Critical
CVE-2018-14933
NUUO · NVRmini Devices
Added Dec 18, 2024
NUUO NVRmini Devices OS Command Injection Vulnerability
Critical
CVE-2024-55956
Cleo · Multiple Products
Added Dec 17, 2024
Cleo Multiple Products Unauthenticated File Upload Vulnerability
Critical
CVE-2024-35250
Microsoft · Windows
Added Dec 16, 2024
Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability
Critical
CVE-2024-20767
Adobe · ColdFusion
Added Dec 16, 2024
Adobe ColdFusion Improper Access Control Vulnerability
Critical
CVE-2024-50623
Cleo · Multiple Products
Added Dec 13, 2024
Cleo Multiple Products Unrestricted File Upload Vulnerability
Critical
CVE-2024-49138
Microsoft · Windows
Added Dec 10, 2024
Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability
Critical
CVE-2024-51378
CyberPersons · CyberPanel
Added Dec 4, 2024
CyberPanel Incorrect Default Permissions Vulnerability
Critical
CVE-2024-11667
Zyxel · Multiple Firewalls
Added Dec 3, 2024
Zyxel Multiple Firewalls Path Traversal Vulnerability
Critical
CVE-2024-11680
ProjectSend · ProjectSend
Added Dec 3, 2024
ProjectSend Improper Authentication Vulnerability
Critical
CVE-2023-45727
North Grid · Proself
Added Dec 3, 2024
North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability
Critical
CVE-2023-28461
Array Networks · AG/vxAG ArrayOS
Added Nov 25, 2024
Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability
Critical
CVE-2024-21287
Oracle · Agile Product Lifecycle Management (PLM)
Added Nov 21, 2024
Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability
Critical
CVE-2024-44309
Apple · Multiple Products
Added Nov 21, 2024
Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability
Critical
CVE-2024-44308
Apple · Multiple Products
Added Nov 21, 2024
Apple Multiple Products Code Execution Vulnerability
Need help prioritizing these vulnerabilities?
ThreatGrid can assess your environment and map active CVEs to your monitored assets.