| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-20767 KEV 📌 💣 | ColdFusion | Improper Access Control (CWE-284) EPSS 0.99 | Adobe | ColdFusion | High | 7.4 | 2024-03-18 11:43:28 | Deep Dive |
| CVE-2024-28255 📌 💣 | Authentication Bypass in OpenMetadata EPSS 0.73 | open-metadata | OpenMetadata | Critical | 9.8 | 2024-03-15 19:55:45 | Deep Dive |
| CVE-2024-1071 📌 💣 | WordPress Plugin Ultimate Member 安全漏洞 EPSS 0.89 | ultimatemember | Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin | Critical | 9.8 | 2024-03-13 15:26:32 | Deep Dive |
| CVE-2023-48788 KEV 📌 💣 | Fortinet FortiClientEMS SQL注入漏洞 EPSS 0.98 | Fortinet | FortiClientEMS | Critical | 9.8 | 2024-03-12 15:09:19 | Deep Dive |
| CVE-2023-49785 🧪 💣 | NextChat vulnerable to Server-Side Request Forgery and Cross-site Scripting EPSS 0.83 | ChatGPTNextWeb | NextChat | Critical | 9.1 | 2024-03-11 23:26:11 | Deep Dive |
| CVE-2024-2044 🧪 💣 | Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4 EPSS 0.79 | pgadmin.org | pgAdmin 4 | Critical | 9.9 | 2024-03-07 20:48:10 | Deep Dive |
| CVE-2024-28156 | Jenkins Build Monitor View Plugin 安全漏洞 EPSS 0.80 | Jenkins Project | Jenkins Build Monitor View Plugin | - | - | 2024-03-06 17:01:59 | Deep Dive |
| CVE-2024-2054 📌 💣 | Artica Proxy Unauthenticated PHP Deserialization Vulnerability EPSS 0.81 | Artica Tech | Artica Proxy | 高危 | - | 2024-03-05 18:56:23 | Deep Dive |
| CVE-2024-27199 KEV 📌 💣 | JetBrains TeamCity 安全漏洞 EPSS 1.00 | JetBrains | TeamCity | High | 7.3 | 2024-03-04 17:21:40 | Deep Dive |
| CVE-2024-27198 KEV 📌 💣 | JetBrains TeamCity 安全漏洞 EPSS 1.00 | JetBrains | TeamCity | Critical | 9.8 | 2024-03-04 17:21:39 | Deep Dive |
| CVE-2024-20328 | ClamAV VirusEvent File Processing Command Injection Vulnerability EPSS 0.85 | Cisco | ClamAV | Medium | 5.3 | 2024-03-01 20:48:15 | Deep Dive |
| CVE-2024-0692 📌 💣 | SolarWinds Security Event Manager Deserialization of Untrusted Data Remote Code Execution Vulnerability EPSS 0.92 | SolarWinds | Security Event Manager | High | 8.8 | 2024-03-01 08:55:36 | Deep Dive |
| CVE-2024-1698 📌 💣 | NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection EPSS 0.78 | wpdevteam | NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar | Critical | 9.8 | 2024-02-27 05:33:12 | Deep Dive |
| CVE-2024-25723 📌 💣 | ZenML 安全漏洞 EPSS 0.71 | - | - | 超危 | - | 2024-02-27 00:00:00 | Deep Dive |
| CVE-2024-1212 KEV 📌 💣 | LoadMaster Pre-Authenticated OS Command Injection EPSS 0.95 | Progress Software | LoadMaster | Critical | 10.0 | 2024-02-21 17:39:13 | Deep Dive |
| CVE-2024-1709 KEV 📌 💣 | Authentication bypass using an alternate path or channel EPSS 1.00 | ConnectWise | ScreenConnect | Critical | 10.0 | 2024-02-21 15:36:04 | Deep Dive |
| CVE-2024-1708 KEV 💣 | Improper limitation of a pathname to a restricted directory (“path traversal”) EPSS 0.88 | ConnectWise | ScreenConnect | High | 8.4 | 2024-02-21 15:29:10 | Deep Dive |
| CVE-2024-1512 📌 💣 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection EPSS 0.78 | stylemix | MasterStudy LMS WordPress Plugin – for Online Courses and Education | Critical | 9.8 | 2024-02-17 07:36:57 | Deep Dive |
| CVE-2024-23478 | SolarWinds Access Rights Manager (ARM) Deserialization of Untrusted Data Remote Code Execution EPSS 0.82 | SolarWinds | Access Rights Manager | High | 8.0 | 2024-02-15 20:35:46 | Deep Dive |
| CVE-2024-25617 | Denial of Service in HTTP Header parser in squid proxy EPSS 0.89 | squid-cache | squid | Medium | 5.3 | 2024-02-14 20:55:52 | Deep Dive |