CVE Database

39807+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43517
8.8 HIGH

Microsoft ActiveX Data Objects Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43516
7.8 HIGH

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-43515
7.5 HIGH

Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43514
7.8 HIGH

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-43511
7.0 HIGH

Windows Kernel Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-43509
7.8 HIGH

Windows Graphics Component Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-43506
7.5 HIGH

BranchCache Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43505
7.8 HIGH

Microsoft Office Visio Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43504
7.8 HIGH

Microsoft Excel Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43503
7.8 HIGH

Microsoft SharePoint Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-43502
7.1 HIGH

Windows Kernel Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-43501
7.8 HIGH

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-43497
8.4 HIGH

DeepSpeed Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43488
8.8 HIGH

Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.

Oct 8, 2024
CVE-2024-43485
7.5 HIGH

.NET and Visual Studio Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43484
7.5 HIGH

.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43483
7.5 HIGH

.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43453
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-38265
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-38262
7.5 HIGH

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-38261
7.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-38229
8.1 HIGH

.NET and Visual Studio Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-38212
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-38179
8.8 HIGH

Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-38149
7.5 HIGH

BranchCache Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-38129
7.5 HIGH

Windows Kerberos Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-38097
7.1 HIGH

Azure Monitor Agent Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-38029
7.5 HIGH

Microsoft OpenSSH for Windows Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-30092
8.0 HIGH

Windows Hyper-V Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-25885
7.5 HIGH

An issue in the getcolor function in utils.py of xhtml2pdf v0.2.13 allows attackers to cause a Regular expression Denial of Service (ReDOS) via supplying a …

Oct 8, 2024
CVE-2024-20659
7.1 HIGH

Windows Hyper-V Security Feature Bypass Vulnerability

Oct 8, 2024
CVE-2024-9381
7.2 HIGH

Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.

Oct 8, 2024
CVE-2024-9380
7.2 HIGH KEV

An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to …

Oct 8, 2024
CVE-2024-9167
7.8 HIGH

Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation.

Oct 8, 2024
CVE-2024-9124
7.5 HIGH

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 600T. If the device is overloaded with requests, it will become unavailable. The device may require …

Oct 8, 2024
CVE-2024-8626
7.5 HIGH

Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple …

Oct 8, 2024
CVE-2024-7612
8.8 HIGH

Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.

Oct 8, 2024
CVE-2024-47011
7.5 HIGH

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information

Oct 8, 2024
CVE-2024-47010
7.3 HIGH

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

Oct 8, 2024
CVE-2024-47009
7.3 HIGH

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

Oct 8, 2024
CVE-2024-47008
7.5 HIGH

Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.

Oct 8, 2024
CVE-2024-47007
7.5 HIGH

A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.

Oct 8, 2024
CVE-2024-8215
8.4 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Platform Payara Server (Admin Console modules) allows Remote Code Inclusion.This …

Oct 8, 2024
CVE-2024-45230
7.5 HIGH

An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to …

Oct 8, 2024
CVE-2024-45880
8.0 HIGH

A command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the SetStationSettings function. The system directly invokes the …

Oct 8, 2024
CVE-2024-45330
7.2 HIGH

A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5 allows attacker to escalate its privileges via specially crafted …

Oct 8, 2024
CVE-2024-8422
7.8 HIGH

CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when application user opens …

Oct 8, 2024
CVE-2024-47562
8.8 HIGH

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralize special elements in user input …

Oct 8, 2024
CVE-2024-47046
7.8 HIGH

A vulnerability has been identified in Simcenter Femap V2306 (All versions), Simcenter Femap V2401 (All versions), Simcenter Femap V2406 (All versions). The affected application is …

Oct 8, 2024
CVE-2024-45475
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Oct 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.