CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21431
7.8 HIGH

Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability

Mar 12, 2024
CVE-2024-21427
7.5 HIGH

Windows Kerberos Security Feature Bypass Vulnerability

Mar 12, 2024
CVE-2024-21426
7.8 HIGH

Microsoft SharePoint Server Remote Code Execution Vulnerability

Mar 12, 2024
CVE-2024-21421
7.5 HIGH

Azure SDK Spoofing Vulnerability

Mar 12, 2024
CVE-2024-21419
7.6 HIGH

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

Mar 12, 2024
CVE-2024-21418
7.8 HIGH

Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2024-21411
8.8 HIGH

Skype for Consumer Remote Code Execution Vulnerability

Mar 12, 2024
CVE-2024-21407
8.1 HIGH

Windows Hyper-V Remote Code Execution Vulnerability

Mar 12, 2024
CVE-2024-21392
7.5 HIGH

.NET and Visual Studio Denial of Service Vulnerability

Mar 12, 2024
CVE-2024-21390
7.1 HIGH

Microsoft Authenticator Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2024-21330
7.8 HIGH

Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2024-27758
8.4 HIGH

In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_netref)), a remote attacker …

Mar 12, 2024
CVE-2024-1529
7.4 HIGH

Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/adduser.php, in multiple parameters. …

Mar 12, 2024
CVE-2024-1528
7.4 HIGH

CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/moduleinterface.php, in multiple parameters. This vulnerability …

Mar 12, 2024
CVE-2024-1302
7.3 HIGH

Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application's file parameter to a …

Mar 12, 2024
CVE-2024-23112
8.0 HIGH

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy …

Mar 12, 2024
CVE-2024-1618
7.8 HIGH

A search path or unquoted item vulnerability in Faronics Deep Freeze Server Standard, which affects versions 8.30.020.4627 and earlier. This vulnerability affects the DFServ.exe file. …

Mar 12, 2024
CVE-2024-1226
7.5 HIGH

The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing HTTP headers. The inclusion of invalidated data in …

Mar 12, 2024
CVE-2023-46717
7.5 HIGH

An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and below when configured with FortiAuthenticator in …

Mar 12, 2024
CVE-2023-42790
8.1 HIGH

A stack-based buffer overflow in Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, FortiProxy 7.4.0, 7.2.0 …

Mar 12, 2024
CVE-2023-36554
8.1 HIGH

A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows …

Mar 12, 2024
CVE-2024-27907
7.8 HIGH

A vulnerability has been identified in Simcenter Femap (All versions < V2306.0000). The affected application contains an out of bounds write past the end of …

Mar 12, 2024
CVE-2024-22045
7.6 HIGH

A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.1 SP1). The product places sensitive information into files or directories that …

Mar 12, 2024
CVE-2024-22044
7.5 HIGH

A vulnerability has been identified in SENTRON 3KC ATC6 Expansion Module Ethernet (3KC9000-8TL75) (All versions). Affected devices expose an unused, unstable http service at port …

Mar 12, 2024
CVE-2024-22041
7.5 HIGH

A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN …

Mar 12, 2024
CVE-2024-22040
7.5 HIGH

A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN …

Mar 12, 2024
CVE-2024-26288
8.7 HIGH

An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected.

Mar 12, 2024
CVE-2024-26004
7.5 HIGH

An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer which may prevent or disrupt the charging functionality.

Mar 12, 2024
CVE-2024-26003
7.5 HIGH

An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt the charging functionality.

Mar 12, 2024
CVE-2024-26002
7.8 HIGH

An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific …

Mar 12, 2024
CVE-2024-26001
7.4 HIGH

An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not …

Mar 12, 2024
CVE-2024-25999
8.4 HIGH

An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service.

Mar 12, 2024
CVE-2024-25998
7.3 HIGH

An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation.

Mar 12, 2024
CVE-2024-27121
7.2 HIGH

Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be …

Mar 12, 2024
CVE-2024-25325
7.1 HIGH

SQL injection vulnerability in Employee Management System v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to the txtemail parameter in …

Mar 12, 2024
CVE-2024-21805
7.8 HIGH

Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnerability is exploited, an …

Mar 12, 2024
CVE-2024-28199
7.1 HIGH

phlex is an open source framework for building object-oriented views in Ruby. There is a potential cross-site scripting (XSS) vulnerability that can be exploited via …

Mar 11, 2024
CVE-2022-46070
7.5 HIGH

GV-ASManager V6.0.1.0 contains a Local File Inclusion vulnerability in GeoWebServer via Path.

Mar 11, 2024
CVE-2024-28197
7.5 HIGH

Zitadel is an open source identity management system. Zitadel uses a cookie to identify the user agent (browser) and its user sessions. Although the cookie …

Mar 11, 2024
CVE-2024-28187
7.2 HIGH

SOY CMS is an open source CMS (content management system) that allows you to build blogs and online shops. SOY CMS versions prior to 3.14.2 …

Mar 11, 2024
CVE-2024-27236
8.4 HIGH

In aoc_unlocked_ioctl of aoc.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional …

Mar 11, 2024
CVE-2024-27233
7.8 HIGH

In ppcfw_init_secpolicy of ppcfw.c, there is a possible permission bypass due to uninitialized data. This could lead to local escalation of privilege with no additional …

Mar 11, 2024
CVE-2024-27229
7.5 HIGH

In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null check. This could lead to remote denial of service …

Mar 11, 2024
CVE-2024-27226
8.4 HIGH

In tmu_config_gov_params of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Mar 11, 2024
CVE-2024-27224
7.8 HIGH

In strncpy of strncpy.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Mar 11, 2024
CVE-2024-27222
7.8 HIGH

In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app cannot access due to Intent Redirect GRANT_URI_PERMISSIONS Attack. This could …

Mar 11, 2024
CVE-2024-27221
7.8 HIGH

In update_policy_data of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Mar 11, 2024
CVE-2024-27220
8.4 HIGH

In lpm_req_handler of , there is a possible out of bounds memory access due to a missing bounds check. This could lead to local escalation …

Mar 11, 2024
CVE-2024-27219
8.4 HIGH

In tmu_set_pi of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Mar 11, 2024
CVE-2024-27213
8.4 HIGH

In BroadcastSystemMessage of servicemgr.cpp, there is a possible Remote Code Execution due to a use after free. This could lead to local escalation of privilege …

Mar 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.