CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38118
5.5 MEDIUM

Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability

Aug 13, 2024
CVE-2024-38117
7.8 HIGH

NTFS Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38116
8.8 HIGH

Windows IP Routing Management Snapin Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38115
8.8 HIGH

Windows IP Routing Management Snapin Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38114
8.8 HIGH

Windows IP Routing Management Snapin Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38109
9.1 CRITICAL

An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.

Aug 13, 2024
CVE-2024-38108
9.3 CRITICAL

Azure Stack Hub Spoofing Vulnerability

Aug 13, 2024
CVE-2024-38107
7.8 HIGH KEV

Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38106
7.0 HIGH KEV

Windows Kernel Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38098
7.8 HIGH

Azure Connected Machine Agent Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38084
7.8 HIGH

Microsoft OfficePlus Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38063
9.8 CRITICAL

Windows TCP/IP Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-37968
7.5 HIGH

Windows DNS Spoofing Vulnerability

Aug 13, 2024
CVE-2024-29995
8.1 HIGH

Windows Kerberos Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-7113

If exploited, this vulnerability could cause a SuiteLink server to consume excessive system resources and slow down processing of Data I/O for the duration of …

Aug 13, 2024
CVE-2024-6619

In Ocean Data Systems Dream Report, an incorrect permission vulnerability could allow a local unprivileged attacker to escalate their privileges and could cause a denial-of-service.

Aug 13, 2024
CVE-2024-6618

In Ocean Data Systems Dream Report, a path traversal vulnerability could allow an attacker to perform remote code execution through the injection of a malicious …

Aug 13, 2024
CVE-2024-41711
6.8 MEDIUM

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an …

Aug 13, 2024
CVE-2024-41614
4.8 MEDIUM

symphonycms <=2.7.10 is vulnerable to Cross Site Scripting (XSS) in the Comment component for articles.

Aug 13, 2024
CVE-2024-41613
5.4 MEDIUM

A Cross Site Scripting (XSS) vulnerability in Symphony CMS 2.7.10 allows remote attackers to inject arbitrary web script or HTML by editing note.

Aug 13, 2024
CVE-2024-37015
7.4 HIGH

An issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the default setting), the SSL/TLS used to establish …

Aug 13, 2024
CVE-2024-36446
8.8 HIGH

The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to conduct an authentication bypass attack due to improper …

Aug 13, 2024
CVE-2024-21981
5.7 MEDIUM

Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrary code execution privilege in ASP …

Aug 13, 2024
CVE-2023-31366
3.3 LOW

Improper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially resulting in denial of service.

Aug 13, 2024
CVE-2023-31356
4.4 MEDIUM

Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, potentially resulting in a loss of data integrity.

Aug 13, 2024
CVE-2023-31349
7.3 HIGH

Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

Aug 13, 2024
CVE-2023-31348
7.3 HIGH

A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

Aug 13, 2024
CVE-2023-31341
7.3 HIGH

Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-of-bounds write, potentially causing …

Aug 13, 2024
CVE-2023-31339
4.8 MEDIUM

Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially …

Aug 13, 2024
CVE-2023-31310
5.0 MEDIUM

Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" …

Aug 13, 2024
CVE-2023-31307
2.3 LOW

Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading …

Aug 13, 2024
CVE-2023-31305
1.9 LOW

Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to reuse IV values to reverse-engineer …

Aug 13, 2024
CVE-2023-31304
2.3 LOW

Improper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF) to modify the PCIe® lane count and speed, …

Aug 13, 2024
CVE-2023-20591
6.5 MEDIUM

Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, …

Aug 13, 2024
CVE-2023-20584
5.3 MEDIUM

IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an attacker with privileges and a compromised Hypervisor to …

Aug 13, 2024
CVE-2023-20578
7.5 HIGH

A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications …

Aug 13, 2024
CVE-2023-20518
1.9 LOW

Incomplete cleanup in the ASP may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIOS menu or UEFI shell …

Aug 13, 2024
CVE-2023-20513
3.3 LOW

An insufficient bounds check in PMFW (Power Management Firmware) may allow an attacker to utilize a malicious VF (virtualization function) to send a malformed message, …

Aug 13, 2024
CVE-2023-20512
1.9 LOW

A hardcoded AES key in PMFW may result in a privileged attacker gaining access to the key, potentially resulting in internal debug information leakage.

Aug 13, 2024
CVE-2023-20510
4.7 MEDIUM

An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially resulting in data …

Aug 13, 2024
CVE-2023-20509
5.2 MEDIUM

An insufficient DRAM address validation in PMFW may allow a privileged attacker to perform a DMA read from an invalid DRAM address to SRAM, potentially …

Aug 13, 2024
CVE-2022-23817

Insufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious trusted application to read/write to the …

Aug 13, 2024
CVE-2022-23815
7.5 HIGH

Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary …

Aug 13, 2024
CVE-2021-46772
3.9 LOW

Insufficient input validation in the ABL may allow a privileged attacker with access to the BIOS menu or UEFI shell to tamper with the structure …

Aug 13, 2024
CVE-2021-46746
5.2 MEDIUM

Lack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged attacker with access to AMD signing keys …

Aug 13, 2024
CVE-2021-26387
3.9 LOW

Insufficient access controls in ASP kernel may allow a privileged attacker with access to AMD signing keys and the BIOS menu or UEFI shell to …

Aug 13, 2024
CVE-2021-26367
5.7 MEDIUM

A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an arbitrary address range for the …

Aug 13, 2024
CVE-2021-26344
7.2 HIGH

An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the …

Aug 13, 2024
CVE-2024-7746
9.8 CRITICAL

Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transactions implemented by the …

Aug 13, 2024
CVE-2024-36505
5.1 MEDIUM

An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has …

Aug 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.