CVE-2024-9680
Mozilla · Firefox
Added Oct 15, 2024
Security Bulletins
Active threat advisories and known exploited vulnerabilities.
Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jun 12, 2026.
Critical
Critical
CVE-2024-30088
Microsoft · Windows
Added Oct 15, 2024
Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
Critical
CVE-2024-9380
Ivanti · Cloud Services Appliance (CSA)
Added Oct 9, 2024
Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability
Critical
CVE-2024-9379
Ivanti · Cloud Services Appliance (CSA)
Added Oct 9, 2024
Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability
Critical
CVE-2024-23113
Fortinet · Multiple Products
Added Oct 9, 2024
Fortinet Multiple Products Format String Vulnerability
Critical
CVE-2024-43573
Microsoft · Windows
Added Oct 8, 2024
Microsoft Windows MSHTML Platform Spoofing Vulnerability
Critical
CVE-2024-43572
Microsoft · Windows
Added Oct 8, 2024
Microsoft Windows Management Console Remote Code Execution Vulnerability
Critical
CVE-2024-43047
Qualcomm · Multiple Chipsets
Added Oct 8, 2024
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Critical
CVE-2024-45519
Synacor · Zimbra Collaboration Suite (ZCS)
Added Oct 3, 2024
Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability
Critical
CVE-2024-29824
Ivanti · Endpoint Manager (EPM)
Added Oct 2, 2024
Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability
Critical
CVE-2019-0344
SAP · Commerce Cloud
Added Sep 30, 2024
SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
Critical
CVE-2020-15415
DrayTek · Multiple Vigor Routers
Added Sep 30, 2024
DrayTek Multiple Vigor Routers OS Command Injection Vulnerability
Critical
CVE-2023-25280
D-Link · DIR-820 Router
Added Sep 30, 2024
D-Link DIR-820 Router OS Command Injection Vulnerability
Critical
CVE-2024-7593
Ivanti · Virtual Traffic Manager
Added Sep 24, 2024
Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability
Critical
CVE-2024-8963
Ivanti · Cloud Services Appliance (CSA)
Added Sep 19, 2024
Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability
Critical
CVE-2020-14644
Oracle · WebLogic Server
Added Sep 18, 2024
Oracle WebLogic Server Remote Code Execution Vulnerability
Critical
CVE-2022-21445
Oracle · ADF Faces
Added Sep 18, 2024
Oracle ADF Faces Deserialization of Untrusted Data Vulnerability
Critical
CVE-2020-0618
Microsoft · SQL Server
Added Sep 18, 2024
Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
Critical
CVE-2024-27348
Apache · HugeGraph-Server
Added Sep 18, 2024
Apache HugeGraph-Server Improper Access Control Vulnerability
Critical
CVE-2014-0502
Adobe · Flash Player
Added Sep 17, 2024
Adobe Flash Player Double Free Vulnerablity
Critical
CVE-2013-0648
Adobe · Flash Player
Added Sep 17, 2024
Adobe Flash Player Code Execution Vulnerability
Critical
CVE-2013-0643
Adobe · Flash Player
Added Sep 17, 2024
Adobe Flash Player Incorrect Default Permissions Vulnerability
Critical
CVE-2014-0497
Adobe · Flash Player
Added Sep 17, 2024
Adobe Flash Player Integer Underflow Vulnerablity
Critical
CVE-2024-6670
Progress · WhatsUp Gold
Added Sep 16, 2024
Progress WhatsUp Gold SQL Injection Vulnerability
Critical
CVE-2024-43461
Microsoft · Windows
Added Sep 16, 2024
Microsoft Windows MSHTML Platform Spoofing Vulnerability
Need help prioritizing these vulnerabilities?
ThreatGrid can assess your environment and map active CVEs to your monitored assets.