CVE Database

39716+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-49089
7.2 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49088
7.8 HIGH

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49086
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49085
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49084
7.0 HIGH

Windows Kernel Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49080
8.8 HIGH

Windows IP Routing Management Snapin Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49079
7.8 HIGH

Input Method Editor (IME) Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49076
7.8 HIGH

Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49075
7.5 HIGH

Windows Remote Desktop Services Denial of Service Vulnerability

Dec 12, 2024
CVE-2024-49074
7.8 HIGH

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49072
7.8 HIGH

Windows Task Scheduler Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49070
7.4 HIGH

Microsoft SharePoint Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49069
7.8 HIGH

Microsoft Excel Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49068
8.2 HIGH

Microsoft SharePoint Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49063
8.4 HIGH

Microsoft/Muzic Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49059
7.0 HIGH

Microsoft Office Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49057
8.1 HIGH

Microsoft Defender for Endpoint on Android Spoofing Vulnerability

Dec 12, 2024
CVE-2024-47835
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been detected in the parse_lrc function within gstsubparse.c. The …

Dec 12, 2024
CVE-2024-47778
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in gst_wavparse_adtl_chunk within gstwavparse.c. This vulnerability arises due to …

Dec 12, 2024
CVE-2024-47603
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_update_tracks function within matroska-demux.c. The …

Dec 12, 2024
CVE-2024-47602
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_add_wvpk_header function within matroska-demux.c. This …

Dec 12, 2024
CVE-2024-47601
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_parse_blockgroup_or_simpleblock function within matroska-demux.c. This …

Dec 12, 2024
CVE-2024-47599
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_jpeg_dec_negotiate function in gstjpegdec.c. This …

Dec 12, 2024
CVE-2024-47596
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in the qtdemux_parse_svq3_stsd_data function within qtdemux.c. In the FOURCC_SMI_ case, …

Dec 12, 2024
CVE-2024-47546
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in extract_cc_from_data function within qtdemux.c. In the FOURCC_c708 case, …

Dec 12, 2024
CVE-2024-47545
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in qtdemux_parse_trak function within qtdemux.c. During the strf parsing …

Dec 12, 2024
CVE-2024-47544
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. The function qtdemux_parse_sbgp in qtdemux.c is affected by a null dereference vulnerability. This vulnerability is …

Dec 12, 2024
CVE-2024-47543
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in qtdemux_parse_container function within qtdemux.c. In the parent function …

Dec 12, 2024
CVE-2024-47542
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discovered in the id3v2_read_synch_uint function, located in id3v2.c. If …

Dec 12, 2024
CVE-2024-47541
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. An OOB-write vulnerability has been identified in the gst_ssa_parse_remove_override_codes function of the gstssaparse.c file. This …

Dec 12, 2024
CVE-2024-45404
8.1 HIGH

OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does not exist, an …

Dec 12, 2024
CVE-2024-43600
7.8 HIGH

Microsoft Office Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-43594
7.3 HIGH

Microsoft System Center Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-37401
7.5 HIGH

An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service.

Dec 12, 2024
CVE-2024-37377
7.5 HIGH

A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.

Dec 12, 2024
CVE-2024-12484
7.3 HIGH

A vulnerability classified as critical was found in Codezips Technical Discussion Forum 1.0. This vulnerability affects unknown code of the file /signuppost.php. The manipulation of …

Dec 12, 2024
CVE-2024-12382
8.8 HIGH

Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Dec 12, 2024
CVE-2024-12381
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Dec 12, 2024
CVE-2024-11950
8.8 HIGH

XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Dec 12, 2024
CVE-2024-11949
8.8 HIGH

GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Dec 12, 2024
CVE-2024-11947
8.8 HIGH

GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Dec 12, 2024
CVE-2024-11872
7.8 HIGH

Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Epic Games Launcher. …

Dec 12, 2024
CVE-2024-9845
7.8 HIGH

Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation.

Dec 11, 2024
CVE-2024-8496
7.8 HIGH

Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation.

Dec 11, 2024
CVE-2024-48912
8.1 HIGH

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an authenticated user can use an …

Dec 11, 2024
CVE-2024-47761
7.2 HIGH

GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an administrator with access to the …

Dec 11, 2024
CVE-2024-47760
8.8 HIGH

GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a technician with an access to …

Dec 11, 2024
CVE-2024-11598
7.8 HIGH

Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, or 2023.3 HF3 allows a local authenticated attacker to achieve …

Dec 11, 2024
CVE-2024-11597
7.8 HIGH

Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local authenticated attacker to achieve …

Dec 11, 2024
CVE-2024-10251
7.8 HIGH

Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local authenticated attacker to achieve local privilege escalation.

Dec 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.