CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21315
7.8 HIGH

Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-20673
7.8 HIGH

Microsoft Office Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2024-20667
7.5 HIGH

Azure DevOps Server Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2024-23440
7.1 HIGH

Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability. The 0x22200B IOCTL code of the Vba32m64.sys driver allows to read up to 0x802 …

Feb 13, 2024
CVE-2024-23439
7.1 HIGH

Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability by triggering the 0x22201B, 0x22201F, 0x222023, 0x222027 ,0x22202B, 0x22202F, 0x22203F, 0x222057 and 0x22205B IOCTL …

Feb 13, 2024
CVE-2024-1163
7.1 HIGH

The attacker may exploit a path traversal vulnerability leading to information disclosure.

Feb 13, 2024
CVE-2024-24781
7.5 HIGH

An unauthenticated remote attacker can use an uncontrolled resource consumption vulnerability to DoS the affected devices through excessive traffic on a single ethernet port.

Feb 13, 2024
CVE-2023-6516
7.5 HIGH

To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some …

Feb 13, 2024
CVE-2023-5679
7.5 HIGH

A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are …

Feb 13, 2024
CVE-2023-5517
7.5 HIGH

A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redirect <domain>;` is configured, and - the resolver …

Feb 13, 2024
CVE-2023-4408
7.5 HIGH

The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, …

Feb 13, 2024
CVE-2024-24925
7.8 HIGH

A vulnerability has been identified in Simcenter Femap (All versions < V2306.0000). The affected application is vulnerable to uninitialized pointer access while parsing specially crafted …

Feb 13, 2024
CVE-2024-24924
7.8 HIGH

A vulnerability has been identified in Simcenter Femap (All versions < V2306.0000). The affected application contains an out of bounds write past the end of …

Feb 13, 2024
CVE-2024-24923
7.8 HIGH

A vulnerability has been identified in Simcenter Femap (All versions < V2401.0000), Simcenter Femap (All versions < V2306.0001). The affected applications contain an out of …

Feb 13, 2024
CVE-2024-24922
7.8 HIGH

A vulnerability has been identified in Simcenter Femap (All versions < V2401.0000). The affected application contains an out of bounds write past the end of …

Feb 13, 2024
CVE-2024-24921
7.8 HIGH

A vulnerability has been identified in Simcenter Femap (All versions < V2401.0000). The affected application is vulnerable to memory corruption while parsing specially crafted Catia …

Feb 13, 2024
CVE-2024-24920
7.8 HIGH

A vulnerability has been identified in Simcenter Femap (All versions < V2401.0000). The affected application contains an out of bounds write past the end of …

Feb 13, 2024
CVE-2024-23813
7.3 HIGH

A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector of the affected product lacks proper authentication. …

Feb 13, 2024
CVE-2024-23812
8.0 HIGH

A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application incorrectly neutralizes special elements when creating a report which …

Feb 13, 2024
CVE-2024-23811
8.8 HIGH

A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application allows users to upload arbitrary files via TFTP. This …

Feb 13, 2024
CVE-2024-23810
8.8 HIGH

A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application is vulnerable to SQL injection. This could allow an …

Feb 13, 2024
CVE-2024-23804
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (All versions < V2302.0006). The affected applications …

Feb 13, 2024
CVE-2024-23803
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V2302 (All versions < V2302.0007). The affected application contains an …

Feb 13, 2024
CVE-2024-23802
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (All versions < V2302.0006). The affected applications …

Feb 13, 2024
CVE-2024-23798
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (All versions < V2302.0006). The affected applications …

Feb 13, 2024
CVE-2024-23797
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (All versions < V2302.0006). The affected applications …

Feb 13, 2024
CVE-2024-23796
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (All versions < V2302.0006). The affected application …

Feb 13, 2024
CVE-2024-23795
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (All versions < V2302.0006). The affected application …

Feb 13, 2024
CVE-2024-22042
7.8 HIGH

A vulnerability has been identified in Unicam FX (All versions). The windows installer agent used in affected product contains incorrect use of privileged APIs that …

Feb 13, 2024
CVE-2023-51440
7.5 HIGH

A vulnerability has been identified in SIMATIC CP 343-1 (6GK7343-1EX30-0XE0) (All versions), SIMATIC CP 343-1 Lean (6GK7343-1CX10-0XE0) (All versions), SIPLUS NET CP 343-1 (6AG1343-1EX30-7XE0) (All …

Feb 13, 2024
CVE-2023-50236
7.8 HIGH

A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The affected product is vulnerable due to weak file and folder permissions in …

Feb 13, 2024
CVE-2023-49125
7.8 HIGH

A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.263), Parasolid V35.1 (All versions < V35.1.252), Parasolid V36.0 (All versions < V36.0.198), Solid …

Feb 13, 2024
CVE-2024-22454
8.8 HIGH

Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit …

Feb 13, 2024
CVE-2024-22445
7.2 HIGH

Dell PowerProtect Data Manager, version 19.15 and prior versions, contain an OS command injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, …

Feb 13, 2024
CVE-2023-52431
8.8 HIGH

The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism via an empty form value and an empty cookie (if …

Feb 13, 2024
CVE-2024-22024
8.3 HIGH

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways …

Feb 13, 2024
CVE-2024-25642
7.4 HIGH

Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC breaking the …

Feb 13, 2024
CVE-2024-24743
8.6 HIGH

SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious request with a crafted XML file …

Feb 13, 2024
CVE-2024-22132
7.4 HIGH

SAP IDES ECC-systems contain code that permits the execution of arbitrary program code of user's choice.An attacker can therefore control the behaviour of the system …

Feb 13, 2024
CVE-2024-22130
7.6 HIGH

Print preview option in SAP CRM WebClient UI - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, S4FND 108, WEBCUIF …

Feb 13, 2024
CVE-2024-25407
7.5 HIGH

SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service …

Feb 13, 2024
CVE-2024-24337
8.0 HIGH

CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into …

Feb 12, 2024
CVE-2024-23762
7.8 HIGH

Unrestricted File Upload vulnerability in Content Manager feature in Gambio 4.9.2.0 allows attackers to execute arbitrary code via upload of crafted PHP file.

Feb 12, 2024
CVE-2024-23833
7.5 HIGH

OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability exists in OpenRefine(version<=3.7.7) where an …

Feb 12, 2024
CVE-2024-22228
7.8 HIGH

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping …

Feb 12, 2024
CVE-2024-22227
7.8 HIGH

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_dc utility. An authenticated attacker could potentially exploit this vulnerability, leading …

Feb 12, 2024
CVE-2024-22225
7.8 HIGH

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, leading …

Feb 12, 2024
CVE-2024-22224
7.8 HIGH

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping …

Feb 12, 2024
CVE-2024-22223
7.8 HIGH

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_cbr utility. An authenticated malicious user with local access could potentially …

Feb 12, 2024
CVE-2024-22222
7.8 HIGH

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_udoctor utility. An authenticated malicious user with local access could potentially …

Feb 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.