CVE Trends
BetaUpdated an hour ago
FeedsAt a glance
Hypemeter
Current score
Colder than a datacentre floor
Trending
Top 10 CVEs trending on social media within the last 24 hours.
Trending
Hype score
Published
Description
Last 24 hours
- show more detail1CVE-2024-43451
medium 6.5
Exploit known
17
Nov 12, 2024
NTLM Hash Disclosure Spoofing Vulnerability
- show more detail2CVE-2024-49039
high 8.8
Exploit known
17
Nov 12, 2024
Windows Task Scheduler Elevation of Privilege Vulnerability
- show more detail3CVE-2024-28888
high 8.8
7
Oct 2, 2024
A use-after-free vulnerability exists in the way Foxit Reade 2024.1.0.23997 handles a checkbox field object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.
- show more detail4CVE-2024-8068
medium 5.1
6
Nov 12, 2024
Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain
- show more detail5
6
Nov 12, 2024
Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server
- show more detail6CVE-2024-9487
critical 9.5
5
Oct 10, 2024
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning of users and access to the instance. Exploitation required the encrypted assertions feature to be enabled, and the attacker would require direct network access as well as a signed SAML response or metadata document. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.15 and was fixed in versions 3.11.16, 3.12.10, 3.13.5, and 3.14.2. This vulnerability was reported via the GitHub Bug Bounty program.
- show more detail7CVE-2024-4985
critical 10.0
5
May 20, 2024
An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional encrypted assertions feature. This vulnerability allowed an attacker to forge a SAML response to provision and/or gain access to a user with site administrator privileges. Exploitation of this vulnerability would allow unauthorized access to the instance without requiring prior authentication. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.13.0 and was fixed in versions 3.9.15, 3.10.12, 3.11.10 and 3.12.4. This vulnerability was reported via the GitHub Bug Bounty program.
- show more detail8CVE-2024-28987
critical 9.1
Exploit known
2
Aug 21, 2024
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
- show more detail9CVE-2024-47460
critical 9.0
1
Nov 5, 2024
Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
- show more detail10CVE-2024-42509
critical 9.8
1
Nov 5, 2024
Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Trending
Top 10 CVEs trending on social media within the last 24 hours.