CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21343
5.9 MEDIUM

Windows Network Address Translation (NAT) Denial of Service Vulnerability

Feb 13, 2024
CVE-2024-21341
6.8 MEDIUM

Windows Kernel Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2024-21340
4.6 MEDIUM

Windows Kernel Information Disclosure Vulnerability

Feb 13, 2024
CVE-2024-21339
6.4 MEDIUM

Windows USB Generic Parent Driver Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2024-21304
4.1 MEDIUM

Trusted Compute Base Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-20695
5.7 MEDIUM

Skype for Business Information Disclosure Vulnerability

Feb 13, 2024
CVE-2024-20684
6.5 MEDIUM

Windows Hyper-V Denial of Service Vulnerability

Feb 13, 2024
CVE-2024-20679
6.5 MEDIUM

Azure Stack Hub Spoofing Vulnerability

Feb 13, 2024
CVE-2023-50808
6.1 MEDIUM

Zimbra Collaboration before Kepler 9.0.0 Patch 38 GA allows DOM-based JavaScript injection in the Modern UI.

Feb 13, 2024
CVE-2023-48432
6.1 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. XSS, with resultant session stealing, can occur via JavaScript code in a link …

Feb 13, 2024
CVE-2023-45207
6.1 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. An attacker can send a PDF document through mail that contains malicious JavaScript. …

Feb 13, 2024
CVE-2023-45206
6.1 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. Through the help document endpoint in webmail, an attacker can inject JavaScript or …

Feb 13, 2024
CVE-2023-26562
6.5 MEDIUM

In Zimbra Collaboration (ZCS) 8.8.15 and 9.0, a closed account (with 2FA and generated passwords) can send e-mail messages when configured for Imap/smtp.

Feb 13, 2024
CVE-2024-1140
6.1 MEDIUM

Twister Antivirus v8.17 is vulnerable to an Out-of-bounds Read vulnerability by triggering the 0x801120B8 IOCTL code of the filmfd.sys driver.

Feb 13, 2024
CVE-2024-1096
5.5 MEDIUM

Twister Antivirus v8.17 is vulnerable to a Denial of Service vulnerability by triggering the 0x80112067, 0x801120CB 0x801120CC 0x80112044, 0x8011204B, 0x8011204F, 0x80112057, 0x8011205B, 0x8011205F, 0x80112063, 0x8011206F, …

Feb 13, 2024
CVE-2024-24782
4.3 MEDIUM

An unauthenticated attacker can send a ping request from one network to another through an error in the origin verification even though the ports are …

Feb 13, 2024
CVE-2024-1309
6.5 MEDIUM

Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niagara Framework: before Niagara AX 3.8.1, before Niagara …

Feb 13, 2024
CVE-2023-5680
5.3 MEDIUM

If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node …

Feb 13, 2024
CVE-2024-1160
5.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Link in all versions up to, and including, …

Feb 13, 2024
CVE-2024-1159
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.8.0 …

Feb 13, 2024
CVE-2024-1157
5.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button URL in all versions up to, and including, …

Feb 13, 2024
CVE-2023-6072
4.6 MEDIUM

A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing arbitrary …

Feb 13, 2024
CVE-2023-48364
6.5 MEDIUM

A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMATIC …

Feb 13, 2024
CVE-2023-48363
6.5 MEDIUM

A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMATIC …

Feb 13, 2024
CVE-2023-6815
6.5 MEDIUM

Incorrect Privilege Assignment vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series Safety CPU R08/16/32/120SFCPU all versions and MELSEC iQ-R Series SIL2 Process CPU R08/16/32/120PSFCPU all …

Feb 13, 2024
CVE-2024-25914
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Photoboxone SMTP Mail.This issue affects SMTP Mail: from n/a through 1.3.20.

Feb 13, 2024
CVE-2024-21491
5.9 MEDIUM

Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths …

Feb 13, 2024
CVE-2024-25643
4.3 MEDIUM

The SAP Fiori app (My Overtime Request) - version 605, does not perform the necessary authorization checks for an authenticated user which may result in …

Feb 13, 2024
CVE-2024-24741
4.3 MEDIUM

SAP Master Data Governance for Material Data - versions 618, 619, 620, 621, 622, 800, 801, 802, 803, 804, does not perform necessary authorization check …

Feb 13, 2024
CVE-2024-22129
5.4 MEDIUM

SAP Companion - version <3.1.38, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to …

Feb 13, 2024
CVE-2024-24742
4.1 MEDIUM

SAP CRM WebClient UI - version S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF …

Feb 13, 2024
CVE-2024-24740
5.3 MEDIUM

SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.93, KERNEL 7.94, KRNL64UC 7.53, under certain …

Feb 13, 2024
CVE-2024-24739
6.3 MEDIUM

SAP Bank Account Management (BAM) allows an authenticated user with restricted access to use functions which can result in escalation of privileges with low impact …

Feb 13, 2024
CVE-2023-50358
5.8 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands …

Feb 13, 2024
CVE-2023-47218
5.8 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands …

Feb 13, 2024
CVE-2024-22128
4.7 MEDIUM

SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not sufficiently …

Feb 13, 2024
CVE-2024-22126
6.1 MEDIUM

The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters before including them …

Feb 13, 2024
CVE-2023-52060
4.3 MEDIUM

A Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via a crafted request.

Feb 13, 2024
CVE-2023-52059
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Gestsup v3.2.46 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description …

Feb 13, 2024
CVE-2023-49339
6.5 MEDIUM

Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData endpoint.

Feb 13, 2024
CVE-2024-25112
5.5 MEDIUM

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A denial-of-service was found in Exiv2 …

Feb 12, 2024
CVE-2024-24826
5.5 MEDIUM

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in …

Feb 12, 2024
CVE-2023-52430
6.1 MEDIUM

The caddy-security plugin 1.1.20 for Caddy allows reflected XSS via a GET request to a URL that contains an XSS payload and begins with either …

Feb 12, 2024
CVE-2023-28018
5.5 MEDIUM

HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this …

Feb 12, 2024
CVE-2024-1459
5.3 MEDIUM

A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for …

Feb 12, 2024
CVE-2024-1250
6.5 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with …

Feb 12, 2024
CVE-2022-22506
4.6 MEDIUM

IBM Robotic Process Automation 21.0.2 contains a vulnerability that could allow user ids may be exposed across tenants. IBM X-Force ID: 227293.

Feb 12, 2024
CVE-2024-22230
6.4 MEDIUM

Dell Unity, versions prior to 5.4, contains a Cross-site scripting vulnerability. An authenticated attacker could potentially exploit this vulnerability, stealing session information, masquerading as the …

Feb 12, 2024
CVE-2024-22221
4.5 MEDIUM

Dell Unity, versions prior to 5.4, contains SQL Injection vulnerability. An authenticated attacker could potentially exploit this vulnerability, leading to exposure of sensitive information.

Feb 12, 2024
CVE-2024-0169
5.7 MEDIUM

Dell Unity, version(s) 5.3 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote …

Feb 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.