CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38119
7.5 HIGH

Windows Network Address Translation (NAT) Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-38046
7.8 HIGH

PowerShell Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38045
8.1 HIGH

Windows TCP/IP Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-38018
8.8 HIGH

Microsoft SharePoint Server Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-38014
7.8 HIGH KEV

Windows Installer Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-37980
8.8 HIGH

Microsoft SQL Server Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-37966
7.1 HIGH

Microsoft SQL Server Native Scoring Information Disclosure Vulnerability

Sep 10, 2024
CVE-2024-37965
8.8 HIGH

Microsoft SQL Server Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-37342
7.1 HIGH

Microsoft SQL Server Native Scoring Information Disclosure Vulnerability

Sep 10, 2024
CVE-2024-37341
8.8 HIGH

Microsoft SQL Server Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-37340
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-37339
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-37338
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-37337
7.1 HIGH

Microsoft SQL Server Native Scoring Information Disclosure Vulnerability

Sep 10, 2024
CVE-2024-37335
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-30073
7.8 HIGH

Windows Security Zone Mapping Security Feature Bypass Vulnerability

Sep 10, 2024
CVE-2024-26191
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-26186
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-21416
8.1 HIGH

Windows TCP/IP Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2023-6841
7.5 HIGH

A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests …

Sep 10, 2024
CVE-2024-6876
4.4 MEDIUM

Out-of-Bounds read vulnerability in OSCAT Basic Library allows an local, unprivileged attacker to access limited internal data of the PLC which may lead to a …

Sep 10, 2024
CVE-2024-45595
6.1 MEDIUM

D-Tale is a visualizer for Pandas data structures. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code …

Sep 10, 2024
CVE-2024-45593
9.0 CRITICAL

Nix is a package manager for Linux and other Unix systems. A bug in Nix 2.24 prior to 2.24.6 allows a substituter or malicious user …

Sep 10, 2024
CVE-2024-45592
8.2 HIGH

auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Prior to version 5.2.6, there is an unescaped entity property enabling Javascript …

Sep 10, 2024
CVE-2024-45591
5.3 MEDIUM

XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker knows the name. …

Sep 10, 2024
CVE-2024-45590
7.5 HIGH

body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially …

Sep 10, 2024
CVE-2024-45412
5.3 MEDIUM

Yeti bridges the gap between CTI and DFIR practitioners by providing a Forensics Intelligence platform and pipeline. Remote user-controlled data tags can reach a Unicode …

Sep 10, 2024
CVE-2024-45407
6.5 MEDIUM

Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing process may inadvertantly allow access to an …

Sep 10, 2024
CVE-2024-44815
4.6 MEDIUM

Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.

Sep 10, 2024
CVE-2024-44677
9.8 CRITICAL

eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.

Sep 10, 2024
CVE-2024-44676
4.8 MEDIUM

eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreController. java.

Sep 10, 2024
CVE-2024-31960
7.8 HIGH

An issue was discovered in Samsung Mobile Processor Exynos 1480, Exynos 2400. The xclipse amdgpu driver has a reference count bug. This can lead to …

Sep 10, 2024
CVE-2023-37234
9.8 CRITICAL

Loftware Spectrum through 4.6 has unprotected JMX Registry.

Sep 10, 2024
CVE-2023-37233
8.8 HIGH

Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.

Sep 10, 2024
CVE-2023-37232
7.5 HIGH

Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.

Sep 10, 2024
CVE-2023-36103
9.8 CRITICAL

Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.

Sep 10, 2024
CVE-2024-45393
6.4 MEDIUM

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can access webhook …

Sep 10, 2024
CVE-2024-45323
4.3 MEDIUM

An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated …

Sep 10, 2024
CVE-2024-45044
8.8 HIGH

Bareos is open source software for backup, archiving, and recovery of data for operating systems. When a command ACL is in place and a user …

Sep 10, 2024
CVE-2024-43800
5.0 MEDIUM

serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched …

Sep 10, 2024
CVE-2024-43799
5.0 MEDIUM

Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted …

Sep 10, 2024
CVE-2024-43796
5.0 MEDIUM

Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted …

Sep 10, 2024
CVE-2024-42423
6.1 MEDIUM

Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user …

Sep 10, 2024
CVE-2024-36511
3.7 LOW

An improperly implemented security check for standard vulnerability [CWE-358] in FortiADC Web Application Firewall (WAF) 7.4.0 through 7.4.4, 7.2 all versions, 7.1 all versions, 7.0 …

Sep 10, 2024
CVE-2024-35282
4.2 MEDIUM

A cleartext storage of sensitive information in memory vulnerability [CWE-316] affecting FortiClient VPN iOS 7.2 all versions, 7.0 all versions, 6.4 all versions, 6.2 all …

Sep 10, 2024
CVE-2024-33508
7.3 HIGH

An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow …

Sep 10, 2024
CVE-2024-31490
4.3 MEDIUM

An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox …

Sep 10, 2024
CVE-2024-31489
6.8 MEDIUM

AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0.11, FortiClientLinux 7.2.0, 7.0.0 through 7.0.11 and FortiClientMac 7.0.0 through 7.0.11, 7.2.0 …

Sep 10, 2024
CVE-2024-27257
4.3 MEDIUM

IBM OpenPages 8.3 and 9.0 potentially exposes information about client-side source code through use of JavaScript source maps to unauthorized users.

Sep 10, 2024
CVE-2024-25074
5.9 MEDIUM

An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, …

Sep 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.