MITRE ATT&CK CVE list for this attack path. Use risk scores and timeline to decide what to patch first and what to track next.
| CVE | 説明 | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|
| CVE-2024-20439 KEV | A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this vulnerability by using the static credentials to login to the affected system. A successful exploit could allow the attacker to login to the affected system with administrative rights ove | 9.8 | 92.06% | 2024-09-04 | 2026-06-17 |
| CVE-2024-45195 KEV | Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue. | 7.5 | 99.98% | 2024-09-04 | 2026-06-17 |
| CVE-2024-38197 | Microsoft Teams for iOS Spoofing Vulnerability | 6.5 | 16.08% | 2024-08-13 | 2026-06-17 |
| CVE-2024-7297 | Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin privileges by performing a mass assignment request on the '/api/v1/users' endpoint. | 8.8 | 21.35% | 2024-07-30 | 2026-06-17 |
| CVE-2024-38112 KEV | Windows MSHTML Platform Spoofing Vulnerability | 7.5 | 84.34% | 2024-07-09 | 2026-06-17 |
| CVE-2024-3596 | RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature. | 9.0 | 14.86% | 2024-07-09 | 2026-06-17 |
| CVE-2024-38368 | trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older pods which migrated from the pre-2014 pull request workflow to trunk. If the pods had never been claimed then it was still possible to do so. It was also possible to have all owners removed from a pod, and that made the pod available for the same claiming system. This was patched server-side in commit 71be5440906b6bdfbc0bcc7f8a9fec33367ea0f4 in September 2023. | 9.3 | 14.85% | 2024-07-01 | 2026-06-17 |
| CVE-2024-38367 | trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. Prior to commit d4fa66f49cedab449af9a56a21ab40697b9f7b97, the trunk sessions verification step could be manipulated for owner session hijacking Compromising a victim’s session will result in a full takeover of the CocoaPods trunk account. The threat actor could manipulate their pod specifications, disrupt the distribution of legitimate libraries, or cause widespread disruption within the CocoaPods ecosystem. | 8.2 | 11.13% | 2024-07-01 | 2026-06-17 |
| CVE-2024-6387 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. | 8.1 | 99.51% | 2024-07-01 | 2026-06-17 |
| CVE-2024-35250 KEV | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 7.8 | 25.22% | 2024-06-11 | 2026-06-17 |
| CVE-2024-30088 KEV | Windows Kernel Elevation of Privilege Vulnerability | 7.0 | 68.20% | 2024-06-11 | 2026-06-17 |
| CVE-2024-5452 | A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the `deepdiff` library. The library uses `deepdiff.Delta` objects to modify application state based on frontend actions. However, it is possible to bypass the intended restrictions on modifying dunder attributes, allowing an attacker to construct a serialized delta that passes the deserializer | 9.8 | 26.49% | 2024-06-06 | 2026-06-17 |
| CVE-2024-28999 | The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console. | 6.4 | 13.91% | 2024-06-04 | 2026-06-17 |
| CVE-2024-32002 | Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in | 9.0 | 25.33% | 2024-05-14 | 2026-06-17 |
| CVE-2024-2340 | The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada created form with a file upload mechanism. | 5.3 | 28.00% | 2024-04-09 | 2026-06-17 |
| CVE-2024-26218 | Windows Kernel Elevation of Privilege Vulnerability | 7.8 | 12.92% | 2024-04-09 | 2026-06-17 |
| CVE-2024-26209 | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | 5.5 | 14.81% | 2024-04-09 | 2026-06-17 |
| CVE-2024-26158 | Microsoft Install Service Elevation of Privilege Vulnerability | 7.8 | 12.26% | 2024-04-09 | 2026-06-17 |
| CVE-2024-27983 | An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is abruptly closed by the client triggering the Http2Session destructor while header frames are still being processed (and stored in memory) causing a race condition. | 8.2 | 87.21% | 2024-04-08 | 2026-06-17 |
| CVE-2024-2511 | Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service This problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is being used (but not if early_data support is also configured and the default anti-replay protection is in use). In this case, under certain condition | 5.9 | 54.03% | 2024-04-08 | 2026-06-17 |