CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
15 results Clear all
CVE-2024-7699 8.8 HIGH EPSS 0.01
Phoenixcontact TC Mguard Rs4000 4G Vz... - OS Command Injection
An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.
CWE-78 Sep 10, 2024
CVE-2024-7698 5.7 MEDIUM EPSS 0.00
Phoenixcontact TC Mguard Rs4000 4G Vzw VPN Firmware < 8.9.3 - CSRF
A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks.
CWE-201 Sep 10, 2024
CVE-2024-43393 8.1 HIGH EPSS 0.01
Phoenixcontact TC Mguard Rs4000 4G Vzw VPN Firmware - Code Injection
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP FW_RULESETS.FROM_IP FW_RULESETS.IN_IP environment variable which can lead to a DoS.
CWE-94 Sep 10, 2024
CVE-2024-43392 8.1 HIGH EPSS 0.00
Phoenixcontact TC Mguard Rs4000 4G Vzw VPN Firmware - Code Injection
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP environment variable which can lead to a DoS.
CWE-94 Sep 10, 2024
CVE-2024-43391 8.1 HIGH EPSS 0.01
Phoenixcontact TC Mguard Rs4000 4G Vzw VPN Firmware - Code Injection
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment variable which can lead to a DoS.
CWE-94 Sep 10, 2024
CVE-2024-43390 8.1 HIGH EPSS 0.01
Phoenixcontact TC Mguard Rs4000 4G Vzw VPN Firmware - Code Injection
A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can lead to a DoS.
CWE-94 Sep 10, 2024
CVE-2024-43389 8.1 HIGH EPSS 0.01
Phoenixcontact TC Mguard Rs4000 4G Vzw VPN Firmware - Code Injection
A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS.
CWE-94 Sep 10, 2024
CVE-2024-43388 8.8 HIGH EPSS 0.01
Phoenixcontact TC Mguard Rs4000 4G Vzw VPN Firmware - Code Injection
A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.
CWE-94 Sep 10, 2024
CVE-2024-43387 8.8 HIGH EPSS 0.01
Phoenixcontact TC Mguard Rs4000 4G Vz... - OS Command Injection
A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard devices.
CWE-78 Sep 10, 2024
CVE-2024-43386 8.8 HIGH EPSS 0.02
Phoenixcontact TC Mguard Rs4000 4G Vz... - OS Command Injection
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in mGuard devices.
CWE-78 Sep 10, 2024
CVE-2024-43385 8.8 HIGH EPSS 0.02
Phoenixcontact TC Mguard Rs4000 4G Vz... - OS Command Injection
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable PROXY_HTTP_PORT in mGuard devices.
CWE-78 Sep 10, 2024
CVE-2024-7734 5.3 MEDIUM EPSS 0.00
Phoenixcontact TC Mguard Rs4000 4G Vz... - Resource Allocation Without Limits
An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to blocking of valid IPsec VPN peers.
CWE-770 Sep 10, 2024
CVE-2023-2673 5.3 MEDIUM EPSS 0.00
PHOENIX CONTACT FL/TC MGUARD - DoS
Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks.
CWE-1287 Jun 13, 2023
CVE-2022-3480 7.5 HIGH EPSS 0.01
Phoenixcontact FL Mguard Centerport F... - Resource Allocation Without Limits
A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IP’s. Configuring firewall limits for incoming connections cannot prevent the issue.
CWE-770 Nov 15, 2022
CVE-2020-12523 5.4 MEDIUM EPSS 0.00
Phoenix Contact mGuard Devices <8.8.3 - Info Disclosure
On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the LAN side, single switch ports can be disabled by device configuration. After a reboot these ports get functional independent from their configuration setting: Missing Initialization of Resource
CWE-909 Dec 17, 2020