CVE Database

368+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37079
9.8 CRITICAL KEV

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this …

Jun 18, 2024
CVE-2024-6047
9.8 CRITICAL KEV

Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute …

Jun 17, 2024
CVE-2024-32896
7.8 HIGH KEV

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no …

Jun 13, 2024
CVE-2024-34102
9.8 CRITICAL KEV

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result …

Jun 13, 2024
CVE-2024-35250
7.8 HIGH KEV

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

Jun 11, 2024
CVE-2024-30088
7.0 HIGH KEV

Windows Kernel Elevation of Privilege Vulnerability

Jun 11, 2024
CVE-2024-36971
7.8 HIGH KEV

In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be …

Jun 10, 2024
CVE-2024-4577
9.8 CRITICAL KEV

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up …

Jun 9, 2024
CVE-2024-4610
7.8 HIGH KEV

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper …

Jun 7, 2024
CVE-2024-37383
6.1 MEDIUM KEV

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

Jun 7, 2024
CVE-2024-28995
8.6 HIGH KEV

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

Jun 6, 2024
CVE-2024-29824
8.8 HIGH KEV

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-23692
9.8 CRITICAL KEV

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to …

May 31, 2024
CVE-2024-4358
9.8 CRITICAL KEV

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality …

May 29, 2024
CVE-2024-24919
8.6 HIGH KEV

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or …

May 28, 2024
CVE-2024-5274
9.6 CRITICAL KEV

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

May 28, 2024
CVE-2024-4978
8.4 HIGH KEV

Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor …

May 23, 2024
CVE-2024-4947
9.6 CRITICAL KEV

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

May 15, 2024
CVE-2024-30051
7.8 HIGH KEV

Windows DWM Core Library Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30040
8.8 HIGH KEV

Windows MSHTML Platform Security Feature Bypass Vulnerability

May 14, 2024
CVE-2024-4761
8.8 HIGH KEV

Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via …

May 14, 2024
CVE-2024-4671
9.6 CRITICAL KEV

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a …

May 14, 2024
CVE-2024-32113
9.8 CRITICAL KEV

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to …

May 8, 2024
CVE-2023-50224
6.5 MEDIUM KEV

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication …

May 3, 2024
CVE-2024-20359
6.0 MEDIUM KEV

A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security …

Apr 24, 2024
CVE-2024-20353
8.6 HIGH KEV

A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow …

Apr 24, 2024
CVE-2024-4040
9.8 CRITICAL KEV

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files …

Apr 22, 2024
CVE-2024-27348
9.8 CRITICAL KEV

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to …

Apr 22, 2024
CVE-2024-3400
10.0 CRITICAL KEV

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions …

Apr 12, 2024
CVE-2024-29988
8.8 HIGH KEV

SmartScreen Prompt Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-29748
7.8 HIGH KEV

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no …

Apr 5, 2024
CVE-2024-29745
5.5 MEDIUM KEV

there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction …

Apr 5, 2024
CVE-2024-3273
7.3 HIGH KEV

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected …

Apr 4, 2024
CVE-2024-3272
9.8 CRITICAL KEV

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to …

Apr 4, 2024
CVE-2024-29059
7.5 HIGH KEV

.NET Framework Information Disclosure Vulnerability

Mar 23, 2024
CVE-2024-20767
7.4 HIGH KEV

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could …

Mar 18, 2024
CVE-2024-26169
7.8 HIGH KEV

Windows Error Reporting Service Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2023-48788
9.8 CRITICAL KEV

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows …

Mar 12, 2024
CVE-2024-23296
7.8 HIGH KEV

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS …

Mar 5, 2024
CVE-2024-23225
7.8 HIGH KEV

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS …

Mar 5, 2024
CVE-2024-27199
7.3 HIGH KEV

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

Mar 4, 2024
CVE-2024-27198
9.8 CRITICAL KEV

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

Mar 4, 2024
CVE-2024-1212
10.0 CRITICAL KEV

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

Feb 21, 2024
CVE-2024-1709
10.0 CRITICAL KEV

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access …

Feb 21, 2024
CVE-2024-1708
8.4 HIGH KEV

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential …

Feb 21, 2024
CVE-2024-20953
8.8 HIGH KEV

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows …

Feb 17, 2024
CVE-2024-23113
9.8 CRITICAL KEV

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 …

Feb 15, 2024
CVE-2024-21413
9.8 CRITICAL KEV

Microsoft Outlook Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2024-21412
8.1 HIGH KEV

Internet Shortcut Files Security Feature Bypass Vulnerability

Feb 13, 2024
CVE-2024-21410
9.8 CRITICAL KEV

Microsoft Exchange Server Elevation of Privilege Vulnerability

Feb 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.