Vulnerabilities
Summary — last 7 days
New vulnerabilities2,706▼ 533 vs. last week
Critical / high1,274▼ 219 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)254▼ 249 vs. last week
1 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Critical (9.4) | 9.6% | 💥 Exploit | Logonbox Nervepoint Access Manager | 3/21/2019 | 6/17/2026 | An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote attacker to enumerate internal Active Directory usernames and group names, and alter back-end server jobs (backup and synchronization jobs), which could allow for the… |