CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23952
6.5 MEDIUM

This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be triggered by authenticated attacker that …

Feb 14, 2024
CVE-2024-23787
6.5 MEDIUM

Path traversal vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to obtain an arbitrary file …

Feb 14, 2024
CVE-2024-23785
6.5 MEDIUM

Cross-site request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a remote unauthenticated attacker to change the product …

Feb 14, 2024
CVE-2024-23784
6.5 MEDIUM

Improper access control vulnerability exists in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier, which may allow a network-adjacent unauthenticated attacker to …

Feb 14, 2024
CVE-2023-48986
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate …

Feb 14, 2024
CVE-2023-48985
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate …

Feb 14, 2024
CVE-2023-44294
5.4 MEDIUM

In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user …

Feb 14, 2024
CVE-2023-44293
5.4 MEDIUM

In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user …

Feb 14, 2024
CVE-2023-39249
6.3 MEDIUM

Dell SupportAssist for Business PCs version 3.4.0 contains a local Authentication Bypass vulnerability that allows locally authenticated non-admin users to gain temporary privilege within the …

Feb 14, 2024
CVE-2024-22455
4.4 MEDIUM

Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with local access could potentially exploit …

Feb 14, 2024
CVE-2024-25125
5.3 MEDIUM

Digdag is an open source tool that to build, run, schedule, and monitor complex pipelines of tasks across various platforms. Treasure Data's digdag workload automation …

Feb 14, 2024
CVE-2024-24699
6.5 MEDIUM

Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.

Feb 14, 2024
CVE-2024-24698
4.9 MEDIUM

Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.

Feb 14, 2024
CVE-2024-24696
6.8 MEDIUM

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user …

Feb 14, 2024
CVE-2024-24695
6.8 MEDIUM

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user …

Feb 14, 2024
CVE-2024-24690
5.4 MEDIUM

Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.

Feb 14, 2024
CVE-2024-25120
4.3 MEDIUM

TYPO3 is an open source PHP based web content management system released under the GNU GPL. The TYPO3-specific `t3://` URI scheme could be used to …

Feb 13, 2024
CVE-2024-25119
4.9 MEDIUM

TYPO3 is an open source PHP based web content management system released under the GNU GPL. The plaintext value of `$GLOBALS['SYS']['encryptionKey']` was displayed in the …

Feb 13, 2024
CVE-2024-25118
4.3 MEDIUM

TYPO3 is an open source PHP based web content management system released under the GNU GPL. Password hashes were being reflected in the editing forms …

Feb 13, 2024
CVE-2023-6152
5.4 MEDIUM

A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only …

Feb 13, 2024
CVE-2023-31347
4.9 MEDIUM

Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC …

Feb 13, 2024
CVE-2023-31346
6.0 MEDIUM

Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.

Feb 13, 2024
CVE-2023-20579
6.0 MEDIUM

Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in …

Feb 13, 2024
CVE-2024-24751
4.3 MEDIUM

sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access control check …

Feb 13, 2024
CVE-2024-1084
6.5 MEDIUM

Cross-site Scripting in the tag name pattern field in the tag protections UI in GitHub Enterprise Server allows a malicious website that requires user interaction …

Feb 13, 2024
CVE-2024-1082
6.3 MEDIUM

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker to gain unauthorized read permission to files by deploying arbitrary symbolic …

Feb 13, 2024
CVE-2024-21397
5.3 MEDIUM

Microsoft Azure File Sync Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-21381
6.8 MEDIUM

Microsoft Azure Active Directory B2C Spoofing Vulnerability

Feb 13, 2024
CVE-2024-21377
5.5 MEDIUM

Windows DNS Information Disclosure Vulnerability

Feb 13, 2024
CVE-2024-21374
5.0 MEDIUM

Microsoft Teams for Android Information Disclosure Vulnerability

Feb 13, 2024
CVE-2024-21362
5.5 MEDIUM

Windows Kernel Security Feature Bypass Vulnerability

Feb 13, 2024
CVE-2024-21356
6.5 MEDIUM

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

Feb 13, 2024
CVE-2024-21344
5.9 MEDIUM

Windows Network Address Translation (NAT) Denial of Service Vulnerability

Feb 13, 2024
CVE-2024-21343
5.9 MEDIUM

Windows Network Address Translation (NAT) Denial of Service Vulnerability

Feb 13, 2024
CVE-2024-21341
6.8 MEDIUM

Windows Kernel Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2024-21340
4.6 MEDIUM

Windows Kernel Information Disclosure Vulnerability

Feb 13, 2024
CVE-2024-21339
6.4 MEDIUM

Windows USB Generic Parent Driver Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2024-21304
4.1 MEDIUM

Trusted Compute Base Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-20695
5.7 MEDIUM

Skype for Business Information Disclosure Vulnerability

Feb 13, 2024
CVE-2024-20684
6.5 MEDIUM

Windows Hyper-V Denial of Service Vulnerability

Feb 13, 2024
CVE-2024-20679
6.5 MEDIUM

Azure Stack Hub Spoofing Vulnerability

Feb 13, 2024
CVE-2023-50808
6.1 MEDIUM

Zimbra Collaboration before Kepler 9.0.0 Patch 38 GA allows DOM-based JavaScript injection in the Modern UI.

Feb 13, 2024
CVE-2023-48432
6.1 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. XSS, with resultant session stealing, can occur via JavaScript code in a link …

Feb 13, 2024
CVE-2023-45207
6.1 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. An attacker can send a PDF document through mail that contains malicious JavaScript. …

Feb 13, 2024
CVE-2023-45206
6.1 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. Through the help document endpoint in webmail, an attacker can inject JavaScript or …

Feb 13, 2024
CVE-2023-26562
6.5 MEDIUM

In Zimbra Collaboration (ZCS) 8.8.15 and 9.0, a closed account (with 2FA and generated passwords) can send e-mail messages when configured for Imap/smtp.

Feb 13, 2024
CVE-2024-1140
6.1 MEDIUM

Twister Antivirus v8.17 is vulnerable to an Out-of-bounds Read vulnerability by triggering the 0x801120B8 IOCTL code of the filmfd.sys driver.

Feb 13, 2024
CVE-2024-1096
5.5 MEDIUM

Twister Antivirus v8.17 is vulnerable to a Denial of Service vulnerability by triggering the 0x80112067, 0x801120CB 0x801120CC 0x80112044, 0x8011204B, 0x8011204F, 0x80112057, 0x8011205B, 0x8011205F, 0x80112063, 0x8011206F, …

Feb 13, 2024
CVE-2024-24782
4.3 MEDIUM

An unauthenticated attacker can send a ping request from one network to another through an error in the origin verification even though the ports are …

Feb 13, 2024
CVE-2024-1309
6.5 MEDIUM

Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niagara Framework: before Niagara AX 3.8.1, before Niagara …

Feb 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.