25
Recent CVEs
12
Critical Severity
12
High Severity
8.4
Avg CVSS Score
CVE-2025-0078
Critical

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server CVSS: 9.8 08/01/2025

A remote code execution vulnerability exists in Microsoft Exchange Server when the software fails to properly validate input.

Impact

An unauthenticated attacker could execute arbitrary code on the Exchange server.

Mitigation

Apply January 2025 Exchange Server security updates immediately

CVE-2025-0156
Critical

Cisco ASA SSL VPN Authentication Bypass

Cisco ASA CVSS: 9.9 12/01/2025

An authentication bypass vulnerability in Cisco ASA SSL VPN allows unauthenticated access.

Impact

Remote unauthenticated attackers can bypass authentication and gain VPN access.

Mitigation

Upgrade to ASA software version 9.18.4.47 or later

CVE-2025-0203
High

VMware vSphere Client Privilege Escalation

VMware vSphere CVSS: 8.8 15/01/2025

A privilege escalation vulnerability in VMware vSphere Client allows authenticated users to gain administrative privileges.

Impact

Authenticated users with limited privileges can escalate to full administrative access.

Mitigation

Apply VMware security advisory VMSA-2025-0001

CVE-2025-0078
Critical

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server CVSS: 9.8 08/01/2025

A remote code execution vulnerability exists in Microsoft Exchange Server when the software fails to properly validate input.

Impact

An unauthenticated attacker could execute arbitrary code on the Exchange server.

Mitigation

Apply January 2025 Exchange Server security updates immediately

CVE-2025-0156
Critical

Cisco ASA SSL VPN Authentication Bypass

Cisco ASA CVSS: 9.9 12/01/2025

An authentication bypass vulnerability in Cisco ASA SSL VPN allows unauthenticated access.

Impact

Remote unauthenticated attackers can bypass authentication and gain VPN access.

Mitigation

Upgrade to ASA software version 9.18.4.47 or later

CVE-2025-1345
Critical

Jenkins Remote Code Execution via Plugin

Jenkins Jenkins CVSS: 9.8 15/09/2025

A remote code execution vulnerability in Jenkins core allows arbitrary code execution.

Impact

Authenticated attackers can execute arbitrary code on Jenkins servers.

Mitigation

Update to Jenkins 2.426.2 LTS or 2.470 weekly or later

CVE-2025-1167
Critical

Apache Struts Remote Code Execution

Apache Struts CVSS: 9.8 14/08/2025

A remote code execution vulnerability in Apache Struts when processing file uploads.

Impact

Remote attackers can execute arbitrary code on vulnerable Struts applications.

Mitigation

Update to Apache Struts 2.5.33 or 6.3.0.2 or later

CVE-2025-1401
High

Microsoft Teams Remote Code Execution

Microsoft Teams CVSS: 8.8 12/09/2025

A remote code execution vulnerability exists in Microsoft Teams when the application fails to properly sanitize input.

Impact

An attacker could execute arbitrary code in the context of the current user.

Mitigation

Update to Microsoft Teams version 1.7.00.26062 or later

CVE-2025-1234
High

SolarWinds Orion Platform SQL Injection

SolarWinds Orion Platform CVSS: 8.8 03/09/2025

An SQL injection vulnerability in SolarWinds Orion Platform allows unauthorized database access.

Impact

Authenticated attackers can extract sensitive information from the Orion database.

Mitigation

Apply SolarWinds security hotfix 2025.3.1 or later

CVE-2024-38063
Critical

Windows TCP/IP Remote Code Execution Vulnerability

Microsoft Windows CVSS: 9.8 13/08/2024

A remote code execution vulnerability exists in the Windows TCP/IP stack.

Impact

An unauthenticated attacker could send specially crafted IPv6 packets to cause remote code execution.

Mitigation

Apply August 2024 Windows security updates immediately

CVE-2024-38112
High

Windows MSHTML Platform Spoofing Vulnerability

Microsoft Windows MSHTML CVSS: 7.5 09/07/2024

A spoofing vulnerability exists in Windows MSHTML Platform when it improperly validates input.

Impact

An attacker could exploit this vulnerability to spoof content, perform phishing attacks, or redirect users.

Mitigation

Install July 2024 Windows security updates

CVE-2024-38077
Critical

Windows Remote Desktop Licensing Service Remote Code Execution

Microsoft Windows RDS CVSS: 9.8 09/07/2024

A remote code execution vulnerability exists in Windows Remote Desktop Licensing Service.

Impact

An unauthenticated attacker could send a specially crafted request to execute arbitrary code.

Mitigation

Apply July 2024 Windows security updates and restrict RDS access

CVE-2024-5910
Critical

Palo Alto Networks Expedition SQL Injection

Palo Alto Networks Expedition CVSS: 9.3 12/07/2024

An SQL injection vulnerability in Palo Alto Networks Expedition allows unauthenticated attackers to reveal usernames, passwords, device configurations, and device API keys.

Impact

Complete compromise of Expedition tool and connected firewall configurations.

Mitigation

Update to Expedition 1.2.96 or later and reset all credentials

CVE-2024-6778
Critical

Atlassian Confluence Data Center Remote Code Execution

Atlassian Confluence CVSS: 9.8 15/08/2024

Improper neutralization of special elements used in an OS command in Confluence Data Center and Server.

Impact

Unauthenticated attackers can execute arbitrary system commands on the server.

Mitigation

Update to Confluence 8.5.8, 8.9.1, or later versions immediately

CVE-2024-37085
High

VMware ESXi Authentication Bypass

VMware ESXi CVSS: 6.8 25/06/2024

An authentication bypass vulnerability affecting VMware ESXi, Workstation, and Fusion products.

Impact

A malicious actor with sufficient Active Directory permissions can gain full access to an ESXi host.

Mitigation

Apply VMware security updates VMSA-2024-0012

CVE-2024-38178
High

Microsoft Windows Scripting Engine Memory Corruption

Microsoft Windows Scripting Engine CVSS: 7.5 13/08/2024

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft browsers.

Impact

An attacker could corrupt memory in a way that enables arbitrary code execution in the context of the current user.

Mitigation

Install August 2024 Windows and Internet Explorer security updates

CVE-2024-4947
High

Google Chrome Type Confusion Vulnerability

Google Chrome CVSS: 8.8 21/05/2024

Type confusion vulnerability in V8 JavaScript engine in Google Chrome prior to version 125.0.6422.60.

Impact

Remote attackers could potentially exploit heap corruption via a crafted HTML page.

Mitigation

Update to Chrome version 125.0.6422.60 or later

CVE-2024-38200
High

Windows File Explorer Remote Code Execution

Microsoft Windows File Explorer CVSS: 7.8 13/08/2024

A remote code execution vulnerability exists when Windows File Explorer improperly handles calls to Advanced Local Procedure Call (ALPC).

Impact

An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user.

Mitigation

Apply August 2024 Windows security updates

CVE-2024-38213
Medium

Windows Mark of the Web Security Feature Bypass

Microsoft Windows CVSS: 6.5 10/09/2024

A security feature bypass vulnerability exists in Windows when it improperly handles Mark of the Web (MOTW).

Impact

An attacker could bypass Windows Defender SmartScreen checks and execute malicious files.

Mitigation

Install September 2024 Windows security updates

CVE-2024-20767
High

Cisco IOS XE Web UI Privilege Escalation

Cisco IOS XE CVSS: 7.2 27/03/2024

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate privileges.

Impact

An attacker could exploit this vulnerability to gain administrator-level privileges.

Mitigation

Apply Cisco security updates and disable web UI if not required

CVE-2024-20767
High

Cisco IOS XE Web UI Privilege Escalation

Cisco IOS XE CVSS: 7.2 27/03/2024

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate privileges.

Impact

An attacker could exploit this vulnerability to gain administrator-level privileges.

Mitigation

Apply Cisco security updates and disable web UI if not required

CVE-2024-38189
High

Microsoft Project Remote Code Execution Vulnerability

Microsoft Project CVSS: 7.8 13/08/2024

A remote code execution vulnerability exists in Microsoft Project when it fails to properly handle objects in memory.

Impact

An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user.

Mitigation

Apply August 2024 Microsoft Project security updates

CVE-2024-6409
High

OpenSSH Remote Code Execution via Signal Handler

OpenSSH OpenSSH CVSS: 7 08/07/2024

A race condition vulnerability in OpenSSH server signal handler could lead to remote code execution.

Impact

Remote unauthenticated attackers may be able to execute arbitrary code as root.

Mitigation

Update to OpenSSH 9.8p1 or later versions

CVE-2024-38014
High

Windows Installer Elevation of Privilege

Microsoft Windows Installer CVSS: 7.8 11/06/2024

An elevation of privilege vulnerability exists when Windows Installer improperly handles certain file operations.

Impact

An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

Mitigation

Apply June 2024 Windows security updates

CVE-2024-38856
High

Apache HTTP Server SSRF Vulnerability

Apache HTTP Server CVSS: 7.5 17/07/2024

Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server mod_rewrite module.

Impact

Attackers can make the server perform unintended requests to internal or external systems.

Mitigation

Update to Apache HTTP Server 2.4.60 or later

CVE-2024-38202
High

Windows Update Stack Elevation of Privilege

Microsoft Windows Update CVSS: 7.8 13/08/2024

An elevation of privilege vulnerability exists in the Windows Update Stack when it improperly handles calls to Advanced Local Procedure Call (ALPC).

Impact

An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

Mitigation

Install August 2024 Windows security updates

CVE-2024-21762
Critical

Fortinet FortiOS Out-of-bounds Write

Fortinet FortiOS CVSS: 9.6 08/02/2024

An out-of-bounds write vulnerability in FortiOS SSL-VPN may allow a remote unauthenticated attacker to execute arbitrary code.

Impact

Remote code execution on FortiGate devices with SSL-VPN enabled.

Mitigation

Upgrade to FortiOS 7.4.3, 7.2.7, 7.0.14, or disable SSL-VPN if not required

CVE-2024-38095
High

Windows Kernel Elevation of Privilege

Microsoft Windows Kernel CVSS: 7.8 09/07/2024

An elevation of privilege vulnerability exists in the Windows kernel when it fails to properly handle objects in memory.

Impact

An attacker who successfully exploited this vulnerability could run processes in an elevated context.

Mitigation

Apply July 2024 Windows security updates

CVE-2024-23692
Critical

Rejetto HTTP File Server Remote Code Execution

Rejetto HTTP File Server CVSS: 9.8 24/01/2024

A template injection vulnerability in Rejetto HTTP File Server (HFS) allows remote code execution.

Impact

Unauthenticated remote attackers can execute arbitrary commands on the server.

Mitigation

Update to HFS 2.4.0 RC7 or later, or discontinue use if not required

CVE-2024-38106
Medium

Windows Kernel Information Disclosure

Microsoft Windows Kernel CVSS: 5.5 09/07/2024

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory.

Impact

An attacker who successfully exploited this vulnerability could obtain information to further compromise the system.

Mitigation

Install July 2024 Windows security updates

CVE-2024-0519
High

Google Chrome Out-of-bounds Memory Access

Google Chrome CVSS: 8.8 16/01/2024

An out-of-bounds memory access vulnerability in V8 JavaScript engine in Google Chrome.

Impact

Remote attackers could potentially exploit heap corruption via a crafted HTML page.

Mitigation

Update to Chrome version 120.0.6099.224 or later

CVE-2024-21887
High

VMware vCenter Server Privilege Escalation

VMware vCenter Server CVSS: 7.5 20/02/2024

A privilege escalation vulnerability in VMware vCenter Server due to improper permissions.

Impact

Authenticated users with non-administrative privileges may escalate to root.

Mitigation

Apply VMware security patches VMSA-2024-0006

CVE-2024-1212
Critical

Progress Kemp LoadMaster Command Injection

Progress Kemp LoadMaster CVSS: 10 05/02/2024

An unauthenticated command injection vulnerability in Progress Kemp LoadMaster.

Impact

Remote unauthenticated attackers can execute arbitrary system commands.

Mitigation

Upgrade to LoadMaster firmware 7.2.59.1 or later

CVE-2024-0204
Critical

Fortra GoAnywhere MFT Authentication Bypass

Fortra GoAnywhere MFT CVSS: 9.8 22/01/2024

An authentication bypass vulnerability in Fortra GoAnywhere MFT allows unauthorized access.

Impact

Unauthenticated attackers can access the administrative interface and create admin users.

Mitigation

Apply security patch 7.4.1 or later, restrict admin interface access

CVE-2024-21762
Critical

Fortinet FortiOS Out-of-bounds Write

Fortinet FortiOS CVSS: 9.6 08/02/2024

An out-of-bounds write vulnerability in FortiOS SSL-VPN may allow a remote unauthenticated attacker to execute arbitrary code.

Impact

Remote code execution on FortiGate devices with SSL-VPN enabled.

Mitigation

Upgrade to FortiOS 7.4.3, 7.2.7, 7.0.14, or disable SSL-VPN if not required

CVE-2024-23692
Critical

Rejetto HTTP File Server Remote Code Execution

Rejetto HTTP File Server CVSS: 9.8 24/01/2024

A template injection vulnerability in Rejetto HTTP File Server (HFS) allows remote code execution.

Impact

Unauthenticated remote attackers can execute arbitrary commands on the server.

Mitigation

Update to HFS 2.4.0 RC7 or later, or discontinue use if not required

CVE-2024-0519
High

Google Chrome Out-of-bounds Memory Access

Google Chrome CVSS: 8.8 16/01/2024

An out-of-bounds memory access vulnerability in V8 JavaScript engine in Google Chrome.

Impact

Remote attackers could potentially exploit heap corruption via a crafted HTML page.

Mitigation

Update to Chrome version 120.0.6099.224 or later

CVE-2024-21887
High

VMware vCenter Server Privilege Escalation

VMware vCenter Server CVSS: 7.5 20/02/2024

A privilege escalation vulnerability in VMware vCenter Server due to improper permissions.

Impact

Authenticated users with non-administrative privileges may escalate to root.

Mitigation

Apply VMware security patches VMSA-2024-0006

CVE-2024-1212
Critical

Progress Kemp LoadMaster Command Injection

Progress Kemp LoadMaster CVSS: 10 05/02/2024

An unauthenticated command injection vulnerability in Progress Kemp LoadMaster.

Impact

Remote unauthenticated attackers can execute arbitrary system commands.

Mitigation

Upgrade to LoadMaster firmware 7.2.59.1 or later

CVE-2024-0204
Critical

Fortra GoAnywhere MFT Authentication Bypass

Fortra GoAnywhere MFT CVSS: 9.8 22/01/2024

An authentication bypass vulnerability in Fortra GoAnywhere MFT allows unauthorized access.

Impact

Unauthenticated attackers can access the administrative interface and create admin users.

Mitigation

Apply security patch 7.4.1 or later, restrict admin interface access

Need Help Managing Vulnerabilities?

Staying on top of CVEs and security vulnerabilities requires expertise and dedicated resources. Partner with Australia's leading cybersecurity specialists for comprehensive vulnerability management.

Get Free Security Scan