CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38135
7.8 HIGH

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38134
7.8 HIGH

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38133
7.8 HIGH

Windows Kernel Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38132
7.5 HIGH

Windows Network Address Translation (NAT) Denial of Service Vulnerability

Aug 13, 2024
CVE-2024-38131
8.8 HIGH

Clipboard Virtual Channel Extension Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38130
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38128
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38127
7.8 HIGH

Windows Hyper-V Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38126
7.5 HIGH

Windows Network Address Translation (NAT) Denial of Service Vulnerability

Aug 13, 2024
CVE-2024-38125
7.8 HIGH

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38123
4.4 MEDIUM

Windows Bluetooth Driver Information Disclosure Vulnerability

Aug 13, 2024
CVE-2024-38122
5.5 MEDIUM

Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability

Aug 13, 2024
CVE-2024-38121
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38120
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38118
5.5 MEDIUM

Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability

Aug 13, 2024
CVE-2024-38117
7.8 HIGH

NTFS Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38116
8.8 HIGH

Windows IP Routing Management Snapin Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38115
8.8 HIGH

Windows IP Routing Management Snapin Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38114
8.8 HIGH

Windows IP Routing Management Snapin Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38109
9.1 CRITICAL

An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.

Aug 13, 2024
CVE-2024-38108
9.3 CRITICAL

Azure Stack Hub Spoofing Vulnerability

Aug 13, 2024
CVE-2024-38107
7.8 HIGH KEV

Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38106
7.0 HIGH KEV

Windows Kernel Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38098
7.8 HIGH

Azure Connected Machine Agent Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38084
7.8 HIGH

Microsoft OfficePlus Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38063
9.8 CRITICAL

Windows TCP/IP Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-37968
7.5 HIGH

Windows DNS Spoofing Vulnerability

Aug 13, 2024
CVE-2024-29995
8.1 HIGH

Windows Kerberos Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-7113

If exploited, this vulnerability could cause a SuiteLink server to consume excessive system resources and slow down processing of Data I/O for the duration of …

Aug 13, 2024
CVE-2024-6619

In Ocean Data Systems Dream Report, an incorrect permission vulnerability could allow a local unprivileged attacker to escalate their privileges and could cause a denial-of-service.

Aug 13, 2024
CVE-2024-6618

In Ocean Data Systems Dream Report, a path traversal vulnerability could allow an attacker to perform remote code execution through the injection of a malicious …

Aug 13, 2024
CVE-2024-41711
6.8 MEDIUM

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an …

Aug 13, 2024
CVE-2024-41614
4.8 MEDIUM

symphonycms <=2.7.10 is vulnerable to Cross Site Scripting (XSS) in the Comment component for articles.

Aug 13, 2024
CVE-2024-41613
5.4 MEDIUM

A Cross Site Scripting (XSS) vulnerability in Symphony CMS 2.7.10 allows remote attackers to inject arbitrary web script or HTML by editing note.

Aug 13, 2024
CVE-2024-37015
7.4 HIGH

An issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the default setting), the SSL/TLS used to establish …

Aug 13, 2024
CVE-2024-36446
8.8 HIGH

The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to conduct an authentication bypass attack due to improper …

Aug 13, 2024
CVE-2024-21981
5.7 MEDIUM

Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrary code execution privilege in ASP …

Aug 13, 2024
CVE-2023-31366
3.3 LOW

Improper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially resulting in denial of service.

Aug 13, 2024
CVE-2023-31356
4.4 MEDIUM

Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, potentially resulting in a loss of data integrity.

Aug 13, 2024
CVE-2023-31349
7.3 HIGH

Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

Aug 13, 2024
CVE-2023-31348
7.3 HIGH

A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

Aug 13, 2024
CVE-2023-31341
7.3 HIGH

Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-of-bounds write, potentially causing …

Aug 13, 2024
CVE-2023-31339
4.8 MEDIUM

Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially …

Aug 13, 2024
CVE-2023-31310
5.0 MEDIUM

Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" …

Aug 13, 2024
CVE-2023-31307
2.3 LOW

Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading …

Aug 13, 2024
CVE-2023-31305
1.9 LOW

Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to reuse IV values to reverse-engineer …

Aug 13, 2024
CVE-2023-31304
2.3 LOW

Improper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF) to modify the PCIe® lane count and speed, …

Aug 13, 2024
CVE-2023-20591
6.5 MEDIUM

Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, …

Aug 13, 2024
CVE-2023-20584
5.3 MEDIUM

IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an attacker with privileges and a compromised Hypervisor to …

Aug 13, 2024
CVE-2023-20578
7.5 HIGH

A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications …

Aug 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.