| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-11320 📌 💣 | Command Injection leading to RCE via LDAP Misconfiguration EPSS 0.91 | Pandora FMS | Pandora FMS | - | - | 2024-11-21 10:03:09 | Deep Dive |
| CVE-2024-10400 📌 💣 | Tutor LMS <= 2.7.6 - Unauthenticated SQL Injection via rating_filter EPSS 0.82 | themeum | Tutor LMS – eLearning and online course solution | High | 7.5 | 2024-11-21 07:35:37 | Deep Dive |
| CVE-2024-9474 KEV 📌 💣 | PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface EPSS 0.95 | Palo Alto Networks | Cloud NGFW | Medium | 5.9 | 2024-11-18 15:48:23 | Deep Dive |
| CVE-2024-0012 KEV 📌 💣 | PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) EPSS 1.00 | Palo Alto Networks | Cloud NGFW | Medium | 5.9 | 2024-11-18 15:47:41 | Deep Dive |
| CVE-2024-8856 📌 💣 | Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload EPSS 0.94 | revmakx | Backup and Staging by WP Time Capsule | Critical | 9.8 | 2024-11-16 04:29:16 | Deep Dive |
| CVE-2024-49754 | LibreNMS has a stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/api-access.inc.php EPSS 0.71 | librenms | librenms | High | 7.5 | 2024-11-15 15:11:50 | Deep Dive |
| CVE-2024-10924 📌 💣 | Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass EPSS 0.82 | Really Simple Plugins | Really Simple Security Pro multisite | Critical | 9.8 | 2024-11-15 03:18:46 | Deep Dive |
| CVE-2024-43451 KEV 📌 | NTLM Hash Disclosure Spoofing Vulnerability EPSS 0.84 | Microsoft | Windows Server 2025 | Medium | 6.5 | 2024-11-12 17:53:49 | Deep Dive |
| CVE-2024-43425 📌 💣 | Moodle: remote code execution via calculated question types EPSS 0.83 | - | - | High | 8.1 | 2024-11-07 13:21:59 | Deep Dive |
| CVE-2024-10915 📌 💣 | D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection EPSS 0.79 | D-Link | DNS-320 | High | 8.1 | 2024-11-06 14:00:06 | Deep Dive |
| CVE-2024-10914 📌 💣 | D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection EPSS 0.96 | D-Link | DNS-320 | High | 8.1 | 2024-11-06 13:31:05 | Deep Dive |
| CVE-2024-51378 KEV 🧪 💣 | CyberPanel 安全漏洞 EPSS 0.95 | - | - | Critical | 10.0 | 2024-10-29 00:00:00 | Deep Dive |
| CVE-2024-51567 KEV 🧪 💣 | CyberPanel 安全漏洞 EPSS 0.87 | - | - | Critical | 10.0 | 2024-10-29 00:00:00 | Deep Dive |
| CVE-2024-50623 KEV 📌 💣 | Cleo多款产品 安全漏洞 EPSS 0.99 | - | - | 中危 | - | 2024-10-27 00:00:00 | Deep Dive |
| CVE-2024-47575 KEV 📌 💣 | Fortinet FortiManager 访问控制错误漏洞 EPSS 0.95 | Fortinet | FortiManager | Critical | 9.8 | 2024-10-23 15:03:49 | Deep Dive |
| CVE-2024-46538 📌 | pfSense 安全漏洞 EPSS 0.82 | - | - | - | - | 2024-10-22 00:00:00 | Deep Dive |
| CVE-2024-41713 KEV 📌 💣 | Mitel MiCollab 安全漏洞 EPSS 0.98 | - | - | - | - | 2024-10-21 00:00:00 | Deep Dive |
| CVE-2024-44000 📌 💣 | WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability EPSS 0.82 | LiteSpeed Technologies | LiteSpeed Cache | Critical | 9.8 | 2024-10-20 11:26:23 | Deep Dive |
| CVE-2024-9264 📌 💣 | Grafana SQL Expressions allow for remote code execution EPSS 0.95 | Grafana | Grafana | Critical | 9.9 | 2024-10-18 03:20:52 | Deep Dive |
| CVE-2024-45216 📌 💣 | Apache Solr: Authentication bypass possible using a fake URL Path ending EPSS 0.92 | Apache Software Foundation | Apache Solr | 超危 | - | 2024-10-16 07:50:26 | Deep Dive |