CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20689
7.1 HIGH

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-20688
7.1 HIGH

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-20685
5.9 MEDIUM

Azure Private 5G Core Denial of Service Vulnerability

Apr 9, 2024
CVE-2024-20678
8.8 HIGH

Remote Procedure Call Runtime Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-20670
8.1 HIGH

Outlook for Windows Spoofing Vulnerability

Apr 9, 2024
CVE-2024-20669
6.7 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-20665
6.1 MEDIUM

BitLocker Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-3281
8.8 HIGH

A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build process did …

Apr 9, 2024
CVE-2024-31868
6.1 MEDIUM

Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal users. This issue affects …

Apr 9, 2024
CVE-2024-31866
9.8 CRITICAL

Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding configuration like ZEPPELIN_INTP_CLASSPATH_OVERRIDES. This …

Apr 9, 2024
CVE-2024-31865
6.5 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run …

Apr 9, 2024
CVE-2024-31864
9.8 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database …

Apr 9, 2024
CVE-2024-28235
8.3 HIGH

Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on …

Apr 9, 2024
CVE-2024-31487
5.9 MEDIUM

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 …

Apr 9, 2024
CVE-2024-23671
8.1 HIGH

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 …

Apr 9, 2024
CVE-2024-23662
5.3 MEDIUM

An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and …

Apr 9, 2024
CVE-2024-21756
8.8 HIGH

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, …

Apr 9, 2024
CVE-2024-21755
8.8 HIGH

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, …

Apr 9, 2024
CVE-2023-49913
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49912
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49911
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49910
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49909
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49908
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49907
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49906
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49134
8.1 HIGH

A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926 and Tp-Link …

Apr 9, 2024
CVE-2023-49133
8.1 HIGH

A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926 and Tp-Link …

Apr 9, 2024
CVE-2023-49074
7.4 HIGH

A denial of service vulnerability exists in the TDDP functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially …

Apr 9, 2024
CVE-2023-48784
6.7 MEDIUM

A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.1 and below, version 7.2.7 and below, 7.0 all versions, 6.4 all versions command …

Apr 9, 2024
CVE-2023-48724
7.5 HIGH

A memory corruption vulnerability exists in the web interface functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially …

Apr 9, 2024
CVE-2023-47542
6.7 MEDIUM

A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and below, versions 7.2.4 and below, and 7.0.10 and …

Apr 9, 2024
CVE-2023-47541
6.7 MEDIUM

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 …

Apr 9, 2024
CVE-2023-47540
6.7 MEDIUM

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2.1 through 4.2.6, …

Apr 9, 2024
CVE-2023-45590
9.6 CRITICAL

An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4 allows attacker to execute …

Apr 9, 2024
CVE-2023-41677
7.5 HIGH

A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through …

Apr 9, 2024
CVE-2024-28234
4.3 MEDIUM

Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4, it is possible to inject CSS …

Apr 9, 2024
CVE-2024-28191
3.1 LOW

Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it is possible to inject insert …

Apr 9, 2024
CVE-2024-28190
5.4 MEDIUM

Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, users can inject malicious code in …

Apr 9, 2024
CVE-2023-6320
9.1 CRITICAL

A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A series of specially crafted requests can lead to command …

Apr 9, 2024
CVE-2023-6319
9.1 CRITICAL

A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 through 7. A series of specially crafted requests …

Apr 9, 2024
CVE-2023-6318
9.1 CRITICAL

A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 through 7. A series of specially crafted requests …

Apr 9, 2024
CVE-2023-6317
7.2 HIGH

A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the …

Apr 9, 2024
CVE-2024-31544
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Computer Laboratory Management System v1.0 allows attackers to execute arbitrary JavaScript code by including malicious payloads into “remarks”, …

Apr 9, 2024
CVE-2024-2224
8.1 HIGH

Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary …

Apr 9, 2024
CVE-2024-2223
8.1 HIGH

An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This …

Apr 9, 2024
CVE-2024-31863
5.3 MEDIUM

Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to …

Apr 9, 2024
CVE-2024-3046
7.5 HIGH

In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated user to retrieve …

Apr 9, 2024
CVE-2024-31862
5.3 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are …

Apr 9, 2024
CVE-2022-47894
5.3 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin SAP.This issue affects Apache Zeppelin SAP: from 0.8.0 before 0.11.0. As this project is retired, we do not …

Apr 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.