60452+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.
Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally.
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Bluetooth Port Driver allows an authorized attacker to disclose information locally.
Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally.
Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.
Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.
Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.
Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a …
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.
InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated …
A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation …
A weakness has been identified in aircheng-org iWebShop-5 up to 5.15. The affected element is the function member_list of the file controllers/member.php. This manipulation of …
A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here>
A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector …
A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 …
An integer overflow in the query planning component of MongoDB Server can allow an authenticated user with ordinary database-level read/write privileges to bypass an internal …
MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that …
A security issue in the MongoDB Server aggregation framework allows an authenticated user with limited read privileges to bypass view-level authorization checks and access data …
A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated user with monitoring privileges to access insufficiently protected credentials from concurrent administrative operations. …
A security issue in MongoDB Server allows an authenticated user with write privileges to trigger a persistent fatal assertion crash by sending specially crafted retryable …
A heap out-of-bounds read security issue exists in the query planning component of MongoDB Server. An authenticated user with database read and write privileges can …
A security issue in the MongoDB Server's storage engine integration layer allows an authenticated user with collection creation privileges to cause a persistent denial of …
A use-after-free security issue in the cursor management component of MongoDB Server allows an authenticated user to cause a denial of service. Under specific timing …
Free website and port scanning — find vulnerabilities before attackers do.