CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-26202
7.2 HIGH

DHCP Server Service Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-26200
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-26195
7.2 HIGH

DHCP Server Service Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-26194
7.4 HIGH

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-26193
6.4 MEDIUM

Azure Migrate Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-26189
8.0 HIGH

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-26183
6.5 MEDIUM

Windows Kerberos Denial of Service Vulnerability

Apr 9, 2024
CVE-2024-26180
8.0 HIGH

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-26179
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-26175
7.8 HIGH

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-26172
5.5 MEDIUM

Windows DWM Core Library Information Disclosure Vulnerability

Apr 9, 2024
CVE-2024-26171
6.7 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-26168
6.8 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-26158
7.8 HIGH

Microsoft Install Service Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-21447
7.8 HIGH

Windows Authentication Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-21424
6.5 MEDIUM

Azure Compute Gallery Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-21409
7.3 HIGH

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-21324
7.2 HIGH

Microsoft Defender for IoT Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-21323
8.8 HIGH

Microsoft Defender for IoT Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-21322
7.2 HIGH

Microsoft Defender for IoT Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-20693
7.8 HIGH

Windows Kernel Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-20689
7.1 HIGH

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-20688
7.1 HIGH

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-20685
5.9 MEDIUM

Azure Private 5G Core Denial of Service Vulnerability

Apr 9, 2024
CVE-2024-20678
8.8 HIGH

Remote Procedure Call Runtime Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-20670
8.1 HIGH

Outlook for Windows Spoofing Vulnerability

Apr 9, 2024
CVE-2024-20669
6.7 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-20665
6.1 MEDIUM

BitLocker Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-3281
8.8 HIGH

A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build process did …

Apr 9, 2024
CVE-2024-31868
6.1 MEDIUM

Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal users. This issue affects …

Apr 9, 2024
CVE-2024-31866
9.8 CRITICAL

Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding configuration like ZEPPELIN_INTP_CLASSPATH_OVERRIDES. This …

Apr 9, 2024
CVE-2024-31865
6.5 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run …

Apr 9, 2024
CVE-2024-31864
9.8 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database …

Apr 9, 2024
CVE-2024-28235
8.3 HIGH

Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on …

Apr 9, 2024
CVE-2024-31487
5.9 MEDIUM

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 …

Apr 9, 2024
CVE-2024-23671
8.1 HIGH

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 …

Apr 9, 2024
CVE-2024-23662
5.3 MEDIUM

An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and …

Apr 9, 2024
CVE-2024-21756
8.8 HIGH

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, …

Apr 9, 2024
CVE-2024-21755
8.8 HIGH

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, …

Apr 9, 2024
CVE-2023-49913
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49912
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49911
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49910
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49909
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49908
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49907
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49906
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build …

Apr 9, 2024
CVE-2023-49134
8.1 HIGH

A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926 and Tp-Link …

Apr 9, 2024
CVE-2023-49133
8.1 HIGH

A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926 and Tp-Link …

Apr 9, 2024
CVE-2023-49074
7.4 HIGH

A denial of service vulnerability exists in the TDDP functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially …

Apr 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.