CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20935
6.1 MEDIUM

Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Engineering Change Order). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability …

Feb 17, 2024
CVE-2024-20933
6.1 MEDIUM

Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Engineering Change Order). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability …

Feb 17, 2024
CVE-2024-20929
6.5 MEDIUM

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: DB Privileges). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability …

Feb 17, 2024
CVE-2024-20921
5.9 MEDIUM

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are …

Feb 17, 2024
CVE-2024-20919
5.9 MEDIUM

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are …

Feb 17, 2024
CVE-2024-20915
5.3 MEDIUM

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Login - SSO). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable …

Feb 17, 2024
CVE-2024-20913
5.4 MEDIUM

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). The supported version that is affected is 12.2.1.4.0. Easily …

Feb 17, 2024
CVE-2024-20907
6.1 MEDIUM

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable …

Feb 17, 2024
CVE-2024-20903
6.5 MEDIUM

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.21 and 21.3-21.12. Easily exploitable vulnerability allows low privileged …

Feb 17, 2024
CVE-2023-21833
4.3 MEDIUM

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The supported version that is affected is 8.8. Easily exploitable …

Feb 17, 2024
CVE-2024-21984
5.9 MEDIUM

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a difficult to exploit Reflected Cross-Site Scripting (XSS) vulnerability. Successful exploit requires the attacker …

Feb 16, 2024
CVE-2024-21983
6.5 MEDIUM

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a Denial of Service (DoS) vulnerability. Successful exploit by an authenticated attacker could lead …

Feb 16, 2024
CVE-2024-24750
6.5 MEDIUM

Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very …

Feb 16, 2024
CVE-2024-25083
6.3 MEDIUM

An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low-privileged user initiates a repair, there is an attack vector through …

Feb 16, 2024
CVE-2024-21987
5.4 MEDIUM

SnapCenter versions 4.8 prior to 5.0 are susceptible to a vulnerability which could allow an authenticated SnapCenter Server user to modify system logging configuration settings

Feb 16, 2024
CVE-2024-0020
5.5 MEDIUM

In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a confused deputy. This could …

Feb 16, 2024
CVE-2024-0019
5.0 MEDIUM

In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a missing check for active …

Feb 16, 2024
CVE-2024-0017
5.5 MEDIUM

In shouldUseNoOpLocation of CameraActivity.java, there is a possible confused deputy due to a permissions bypass. This could lead to local information disclosure with no additional …

Feb 16, 2024
CVE-2024-0016
5.3 MEDIUM

In multiple locations, there is a possible out of bounds read due to a missing bounds check. This could lead to paired device information disclosure …

Feb 16, 2024
CVE-2023-40085
5.5 MEDIUM

In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Feb 16, 2024
CVE-2024-22425
6.5 MEDIUM

Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains a brute force/dictionary attack vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to launch …

Feb 16, 2024
CVE-2023-45860
6.5 MEDIUM

In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission …

Feb 16, 2024
CVE-2024-22854
6.1 MEDIUM

DOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61050) and before has been identified. A URL, crafted …

Feb 16, 2024
CVE-2023-49508
6.5 MEDIUM

Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the …

Feb 16, 2024
CVE-2024-0032
6.5 MEDIUM

In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation. This could lead …

Feb 16, 2024
CVE-2024-0030
5.5 MEDIUM

In btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure …

Feb 16, 2024
CVE-2023-40093
5.5 MEDIUM

In multiple files, there is a possible way that trimmed content could be included in PDF output due to a logic error in the code. …

Feb 16, 2024
CVE-2023-40124
5.5 MEDIUM

In multiple locations, there is a possible cross-user read due to a confused deputy. This could lead to local information disclosure of photos or other …

Feb 15, 2024
CVE-2023-40113
5.5 MEDIUM

In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could lead to …

Feb 15, 2024
CVE-2023-40112
5.5 MEDIUM

In ippSetValueTag of ipp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Feb 15, 2024
CVE-2023-40105
5.5 MEDIUM

In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could lead to local information …

Feb 15, 2024
CVE-2024-21728
6.1 MEDIUM

An Open Redirect vulnerability was found in osTicky2 below 2.2.8. osTicky (osTicket Bridge) by SmartCalc is a Joomla 3.x extension that provides Joomla fronted integration …

Feb 15, 2024
CVE-2024-0240
6.5 MEDIUM

A memory leak in the Silicon Labs' Bluetooth stack for EFR32 products may cause memory to be exhausted when sending notifications to multiple clients, this …

Feb 15, 2024
CVE-2024-25373
4.6 MEDIUM

Tenda AC10V4.0 V16.03.10.20 was discovered to contain a stack overflow via the page parameter in the sub_49B384 function.

Feb 15, 2024
CVE-2023-6937
5.3 MEDIUM

wolfSSL prior to 5.6.6 did not check that messages in one (D)TLS record do not span key boundaries. As a result, it was possible to …

Feb 15, 2024
CVE-2024-20718
4.3 MEDIUM

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. …

Feb 15, 2024
CVE-2024-20717
5.4 MEDIUM

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker …

Feb 15, 2024
CVE-2024-20716
4.9 MEDIUM

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to an application denial-of-service. A high-privileged …

Feb 15, 2024
CVE-2023-47537
4.8 MEDIUM

An improper certificate validation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.6, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4 all versions allows a …

Feb 15, 2024
CVE-2023-44253
5.0 MEDIUM

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through …

Feb 15, 2024
CVE-2023-26206
6.8 MEDIUM

An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC 9.4.0 - 9.4.2, 9.2.0 - 9.2.8, 9.1.0 - 9.1.10 and 7.2.0 …

Feb 15, 2024
CVE-2024-20749
5.5 MEDIUM

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024
CVE-2024-20748
5.5 MEDIUM

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024
CVE-2024-20747
5.5 MEDIUM

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024
CVE-2024-20736
5.5 MEDIUM

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024
CVE-2024-20735
5.5 MEDIUM

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024
CVE-2024-20734
5.5 MEDIUM

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker …

Feb 15, 2024
CVE-2024-20733
5.5 MEDIUM

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an Improper Input Validation vulnerability that could lead to an application denial-of-service. An attacker could …

Feb 15, 2024
CVE-2024-1530
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in ECshop 4.1.8. Affected by this issue is some unknown functionality of the file /admin/view_sendlist.php. …

Feb 15, 2024
CVE-2024-20725
5.5 MEDIUM

Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.