CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1482
7.1 HIGH

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create new branches in public repositories and run arbitrary GitHub …

Feb 14, 2024
CVE-2023-50927
8.6 HIGH

Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An attacker can trigger out-of-bounds reads in the RPL-Lite implementation of the RPL protocol …

Feb 14, 2024
CVE-2023-50926
7.5 HIGH

Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds read can be caused by an incoming DIO message when using the …

Feb 14, 2024
CVE-2024-25301
7.2 HIGH

Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php.

Feb 14, 2024
CVE-2023-48229
7.0 HIGH

Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds write exists in the driver for IEEE 802.15.4 radios on nRF platforms …

Feb 14, 2024
CVE-2024-24990
7.5 HIGH

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The …

Feb 14, 2024
CVE-2024-24989
7.5 HIGH

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The …

Feb 14, 2024
CVE-2024-24775
7.5 HIGH

When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. …

Feb 14, 2024
CVE-2024-23982
7.5 HIGH

When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This …

Feb 14, 2024
CVE-2024-23979
7.5 HIGH

When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an …

Feb 14, 2024
CVE-2024-23805
7.5 HIGH

Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility and Reporting module, this may occur when the HTTP Analytics …

Feb 14, 2024
CVE-2024-23314
7.5 HIGH

When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions …

Feb 14, 2024
CVE-2024-23308
7.5 HIGH

When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause …

Feb 14, 2024
CVE-2024-23306
7.1 HIGH

A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files. Note: Software versions which have reached End …

Feb 14, 2024
CVE-2024-22389
7.2 HIGH

When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. …

Feb 14, 2024
CVE-2024-22093
8.7 HIGH

When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can …

Feb 14, 2024
CVE-2024-21849
7.5 HIGH

When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) …

Feb 14, 2024
CVE-2024-21789
7.5 HIGH

When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software …

Feb 14, 2024
CVE-2024-21771
7.5 HIGH

For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic against signatures, resulting in Traffic Management Microkernel …

Feb 14, 2024
CVE-2024-21763
7.5 HIGH

When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclosed queries can cause the Traffic Management …

Feb 14, 2024
CVE-2024-0568
8.8 HIGH

CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering of device configuration over NFC communication.

Feb 14, 2024
CVE-2023-6409
7.7 HIGH

CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application password when opening the file with …

Feb 14, 2024
CVE-2023-6408
8.1 HIGH

CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, …

Feb 14, 2024
CVE-2023-27975
7.1 HIGH

CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with …

Feb 14, 2024
CVE-2023-50868
7.5 HIGH

The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial …

Feb 14, 2024
CVE-2023-50387
7.5 HIGH

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service …

Feb 14, 2024
CVE-2024-25213
7.2 HIGH

Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php.

Feb 14, 2024
CVE-2024-25212
7.2 HIGH

Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.php.

Feb 14, 2024
CVE-2023-5123
8.0 HIGH

The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-json-datasource/ ) is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing JSON data from a …

Feb 14, 2024
CVE-2023-39941
7.1 HIGH

Improper access control in some Intel(R) SUR software before version 2.4.10587 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

Feb 14, 2024
CVE-2023-39425
8.8 HIGH

Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable escalation of privilege via local access.

Feb 14, 2024
CVE-2023-35121
7.8 HIGH

Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow authenticated user to …

Feb 14, 2024
CVE-2023-34351
7.5 HIGH

Buffer underflow in some Intel(R) PCM software before version 202307 may allow an unauthenticated user to potentially enable denial of service via network access.

Feb 14, 2024
CVE-2023-33875
7.1 HIGH

Improper access control for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of …

Feb 14, 2024
CVE-2023-25777
7.9 HIGH

Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege …

Feb 14, 2024
CVE-2023-22342
7.7 HIGH

Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege …

Feb 14, 2024
CVE-2023-22293
8.2 HIGH

Improper access control in the Intel(R) Thunderbolt(TM) DCH drivers for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.

Feb 14, 2024
CVE-2024-23789
8.8 HIGH

Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command on the affected …

Feb 14, 2024
CVE-2024-23788
8.1 HIGH

Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to send an arbitrary …

Feb 14, 2024
CVE-2024-23783
8.8 HIGH

Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to access the affected product …

Feb 14, 2024
CVE-2023-48987
7.5 HIGH

Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, …

Feb 14, 2024
CVE-2023-44283
7.8 HIGH

In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4.1), a security concern has been identified, …

Feb 14, 2024
CVE-2023-25535
7.2 HIGH

Dell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has a high vulnerability that can result in local …

Feb 14, 2024
CVE-2024-24697
7.2 HIGH

Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access.

Feb 14, 2024
CVE-2024-1485
8.0 HIGH

A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing …

Feb 14, 2024
CVE-2024-25121
7.1 HIGH

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File …

Feb 13, 2024
CVE-2023-38960
7.3 HIGH

Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain privileges and execute arbitrary code via crafted executable …

Feb 13, 2024
CVE-2023-20587
7.1 HIGH

Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution.

Feb 13, 2024
CVE-2021-46757
7.8 HIGH

Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel …

Feb 13, 2024
CVE-2024-25122
7.1 HIGH

sidekiq-unique-jobs is an open source project which prevents simultaneous Sidekiq jobs with the same unique arguments to run. Specially crafted GET request parameters handled by …

Feb 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.