CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-26189
8.0 HIGH

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-26180
8.0 HIGH

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-26179
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-26175
7.8 HIGH

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-26158
7.8 HIGH

Microsoft Install Service Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-21447
7.8 HIGH

Windows Authentication Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-21409
7.3 HIGH

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-21324
7.2 HIGH

Microsoft Defender for IoT Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-21323
8.8 HIGH

Microsoft Defender for IoT Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-21322
7.2 HIGH

Microsoft Defender for IoT Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-20693
7.8 HIGH

Windows Kernel Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-20689
7.1 HIGH

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-20688
7.1 HIGH

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-20678
8.8 HIGH

Remote Procedure Call Runtime Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-20670
8.1 HIGH

Outlook for Windows Spoofing Vulnerability

Apr 9, 2024
CVE-2024-3281
8.8 HIGH

A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build process did …

Apr 9, 2024
CVE-2024-28235
8.3 HIGH

Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on …

Apr 9, 2024
CVE-2024-23671
8.1 HIGH

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 …

Apr 9, 2024
CVE-2024-21756
8.8 HIGH

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, …

Apr 9, 2024
CVE-2024-21755
8.8 HIGH

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, …

Apr 9, 2024
CVE-2023-49913
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49912
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49911
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49910
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49909
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49908
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49907
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49906
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49134
8.1 HIGH

A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926 and Tp-Link …

Apr 9, 2024
CVE-2023-49133
8.1 HIGH

A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926 and Tp-Link …

Apr 9, 2024
CVE-2023-49074
7.4 HIGH

A denial of service vulnerability exists in the TDDP functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially …

Apr 9, 2024
CVE-2023-48724
7.5 HIGH

A memory corruption vulnerability exists in the web interface functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially …

Apr 9, 2024
CVE-2023-41677
7.5 HIGH

A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through …

Apr 9, 2024
CVE-2023-6317
7.2 HIGH

A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the …

Apr 9, 2024
CVE-2024-2224
8.1 HIGH

Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary …

Apr 9, 2024
CVE-2024-2223
8.1 HIGH

An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This …

Apr 9, 2024
CVE-2024-3046
7.5 HIGH

In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated user to retrieve …

Apr 9, 2024
CVE-2024-31978
7.6 HIGH

A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP2). Affected devices allow authenticated users to export monitoring data. The corresponding API …

Apr 9, 2024
CVE-2024-31370
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeIsAwesome AIKit aikit-wordpress-ai-writing-assistant-using-gpt3.This issue affects AIKit: from n/a through <= 4.14.1.

Apr 9, 2024
CVE-2024-31367
7.1 HIGH

Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.

Apr 9, 2024
CVE-2024-30191
8.4 HIGH

A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0), SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0), SCALANCE W1788-2 …

Apr 9, 2024
CVE-2024-26275
7.8 HIGH

A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All versions < V36.0.207), Parasolid V36.1 …

Apr 9, 2024
CVE-2023-1082
8.8 HIGH

An remote attacker with low privileges can perform a command injection which can lead to root access.

Apr 9, 2024
CVE-2024-31366
7.1 HIGH

Missing Authorization vulnerability in Themify Post Type Builder (PTB).This issue affects Post Type Builder (PTB): from n/a through 2.0.8.

Apr 9, 2024
CVE-2024-31365
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Post Type Builder (PTB) allows Reflected XSS.This issue affects Post Type Builder …

Apr 9, 2024
CVE-2024-1233
7.3 HIGH

A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or …

Apr 9, 2024
CVE-2024-2975
8.8 HIGH

A race condition was identified through which privilege escalation was possible in certain configurations.

Apr 9, 2024
CVE-2024-27983
8.2 HIGH

An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. …

Apr 9, 2024
CVE-2024-27901
7.2 HIGH

SAP Asset Accounting could allow a high privileged attacker to exploit insufficient validation of path information provided by the users and pass it through to …

Apr 9, 2024
CVE-2024-27899
8.8 HIGH

Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the …

Apr 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.