CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38236
7.5 HIGH

DHCP Server Service Denial of Service Vulnerability

Sep 10, 2024
CVE-2024-38235
6.5 MEDIUM

Windows Hyper-V Denial of Service Vulnerability

Sep 10, 2024
CVE-2024-38234
6.5 MEDIUM

Windows Networking Denial of Service Vulnerability

Sep 10, 2024
CVE-2024-38233
7.5 HIGH

Windows Networking Denial of Service Vulnerability

Sep 10, 2024
CVE-2024-38232
7.5 HIGH

Windows Networking Denial of Service Vulnerability

Sep 10, 2024
CVE-2024-38231
6.5 MEDIUM

Windows Remote Desktop Licensing Service Denial of Service Vulnerability

Sep 10, 2024
CVE-2024-38230
6.5 MEDIUM

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

Sep 10, 2024
CVE-2024-38228
7.2 HIGH

Microsoft SharePoint Server Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-38227
7.2 HIGH

Microsoft SharePoint Server Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-38226
7.3 HIGH KEV

Microsoft Publisher Security Feature Bypass Vulnerability

Sep 10, 2024
CVE-2024-38225
8.8 HIGH

Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38220
9.0 CRITICAL

Azure Stack Hub Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38217
5.4 MEDIUM KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

Sep 10, 2024
CVE-2024-38216
8.2 HIGH

Azure Stack Hub Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38194
8.4 HIGH

An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network.

Sep 10, 2024
CVE-2024-38188
7.1 HIGH

Azure Network Watcher VM Agent Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38119
7.5 HIGH

Windows Network Address Translation (NAT) Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-38046
7.8 HIGH

PowerShell Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38045
8.1 HIGH

Windows TCP/IP Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-38018
8.8 HIGH

Microsoft SharePoint Server Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-38014
7.8 HIGH KEV

Windows Installer Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-37980
8.8 HIGH

Microsoft SQL Server Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-37966
7.1 HIGH

Microsoft SQL Server Native Scoring Information Disclosure Vulnerability

Sep 10, 2024
CVE-2024-37965
8.8 HIGH

Microsoft SQL Server Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-37342
7.1 HIGH

Microsoft SQL Server Native Scoring Information Disclosure Vulnerability

Sep 10, 2024
CVE-2024-37341
8.8 HIGH

Microsoft SQL Server Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-37340
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-37339
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-37338
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-37337
7.1 HIGH

Microsoft SQL Server Native Scoring Information Disclosure Vulnerability

Sep 10, 2024
CVE-2024-37335
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-30073
7.8 HIGH

Windows Security Zone Mapping Security Feature Bypass Vulnerability

Sep 10, 2024
CVE-2024-26191
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-26186
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-21416
8.1 HIGH

Windows TCP/IP Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2023-6841
7.5 HIGH

A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests …

Sep 10, 2024
CVE-2024-6876
4.4 MEDIUM

Out-of-Bounds read vulnerability in OSCAT Basic Library allows an local, unprivileged attacker to access limited internal data of the PLC which may lead to a …

Sep 10, 2024
CVE-2024-45595
6.1 MEDIUM

D-Tale is a visualizer for Pandas data structures. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code …

Sep 10, 2024
CVE-2024-45593
9.0 CRITICAL

Nix is a package manager for Linux and other Unix systems. A bug in Nix 2.24 prior to 2.24.6 allows a substituter or malicious user …

Sep 10, 2024
CVE-2024-45592
8.2 HIGH

auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Prior to version 5.2.6, there is an unescaped entity property enabling Javascript …

Sep 10, 2024
CVE-2024-45591
5.3 MEDIUM

XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker knows the name. …

Sep 10, 2024
CVE-2024-45590
7.5 HIGH

body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially …

Sep 10, 2024
CVE-2024-45412
5.3 MEDIUM

Yeti bridges the gap between CTI and DFIR practitioners by providing a Forensics Intelligence platform and pipeline. Remote user-controlled data tags can reach a Unicode …

Sep 10, 2024
CVE-2024-45407
6.5 MEDIUM

Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing process may inadvertantly allow access to an …

Sep 10, 2024
CVE-2024-44815
4.6 MEDIUM

Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.

Sep 10, 2024
CVE-2024-44677
9.8 CRITICAL

eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.

Sep 10, 2024
CVE-2024-44676
4.8 MEDIUM

eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreController. java.

Sep 10, 2024
CVE-2024-31960
7.8 HIGH

An issue was discovered in Samsung Mobile Processor Exynos 1480, Exynos 2400. The xclipse amdgpu driver has a reference count bug. This can lead to …

Sep 10, 2024
CVE-2023-37234
9.8 CRITICAL

Loftware Spectrum through 4.6 has unprotected JMX Registry.

Sep 10, 2024
CVE-2023-37233
8.8 HIGH

Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.

Sep 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.