CVE-2024-38189
Microsoft · Project
Added Aug 13, 2024
Security Bulletins
Active threat advisories and known exploited vulnerabilities.
Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jun 12, 2026.
Critical
Critical
CVE-2024-32113
Apache · OFBiz
Added Aug 7, 2024
Apache OFBiz Path Traversal Vulnerability
Critical
CVE-2024-36971
Android · Kernel
Added Aug 7, 2024
Android Kernel Remote Code Execution Vulnerability
Critical
CVE-2018-0824
Microsoft · Windows
Added Aug 5, 2024
Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability
Critical
CVE-2024-37085
VMware · ESXi
Added Jul 30, 2024
VMware ESXi Authentication Bypass Vulnerability
Critical
CVE-2023-45249
Acronis · Cyber Infrastructure (ACI)
Added Jul 29, 2024
Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability
Critical
CVE-2024-5217
ServiceNow · Utah, Vancouver, and Washington DC Now Platform
Added Jul 29, 2024
ServiceNow Incomplete List of Disallowed Inputs Vulnerability
Critical
CVE-2024-4879
ServiceNow · Utah, Vancouver, and Washington DC Now Platform
Added Jul 29, 2024
ServiceNow Improper Input Validation Vulnerability
Critical
CVE-2024-39891
Twilio · Authy
Added Jul 23, 2024
Twilio Authy Information Disclosure Vulnerability
Critical
CVE-2012-4792
Microsoft · Internet Explorer
Added Jul 23, 2024
Microsoft Internet Explorer Use-After-Free Vulnerability
Critical
CVE-2022-22948
VMware · vCenter Server
Added Jul 17, 2024
VMware vCenter Server Incorrect Default File Permissions Vulnerability
Critical
CVE-2024-28995
SolarWinds · Serv-U
Added Jul 17, 2024
SolarWinds Serv-U Path Traversal Vulnerability
Critical
CVE-2024-34102
Adobe · Commerce and Magento Open Source
Added Jul 17, 2024
Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
Critical
CVE-2024-36401
OSGeo · GeoServer
Added Jul 15, 2024
OSGeo GeoServer GeoTools Eval Injection Vulnerability
Critical
CVE-2024-23692
Rejetto · HTTP File Server
Added Jul 9, 2024
Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Critical
CVE-2024-38080
Microsoft · Windows
Added Jul 9, 2024
Microsoft Windows Hyper-V Privilege Escalation Vulnerability
Critical
CVE-2024-38112
Microsoft · Windows
Added Jul 9, 2024
Microsoft Windows MSHTML Platform Spoofing Vulnerability
Critical
CVE-2024-20399
Cisco · NX-OS
Added Jul 2, 2024
Cisco NX-OS Command Injection Vulnerability
Critical
CVE-2020-13965
Roundcube · Webmail
Added Jun 26, 2024
Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
Critical
CVE-2022-2586
Linux · Kernel
Added Jun 26, 2024
Linux Kernel Use-After-Free Vulnerability
Critical
CVE-2022-24816
OSGeo · JAI-EXT
Added Jun 26, 2024
OSGeo GeoServer JAI-EXT Code Injection Vulnerability
Critical
CVE-2024-4358
Progress · Telerik Report Server
Added Jun 13, 2024
Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability
Critical
CVE-2024-26169
Microsoft · Windows
Added Jun 13, 2024
Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability
Critical
CVE-2024-32896
Android · Pixel
Added Jun 13, 2024
Android Pixel Privilege Escalation Vulnerability
Critical
CVE-2024-4577
PHP Group · PHP
Added Jun 12, 2024
PHP-CGI OS Command Injection Vulnerability
Need help prioritizing these vulnerabilities?
ThreatGrid can assess your environment and map active CVEs to your monitored assets.