CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21419
7.6 HIGH

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

Mar 12, 2024
CVE-2024-21418
7.8 HIGH

Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2024-21411
8.8 HIGH

Skype for Consumer Remote Code Execution Vulnerability

Mar 12, 2024
CVE-2024-21408
5.5 MEDIUM

Windows Hyper-V Denial of Service Vulnerability

Mar 12, 2024
CVE-2024-21407
8.1 HIGH

Windows Hyper-V Remote Code Execution Vulnerability

Mar 12, 2024
CVE-2024-21400
9.0 CRITICAL

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2024-21392
7.5 HIGH

.NET and Visual Studio Denial of Service Vulnerability

Mar 12, 2024
CVE-2024-21390
7.1 HIGH

Microsoft Authenticator Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2024-21334
9.8 CRITICAL

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

Mar 12, 2024
CVE-2024-21330
7.8 HIGH

Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2024-20671
5.5 MEDIUM

Microsoft Defender Security Feature Bypass Vulnerability

Mar 12, 2024
CVE-2024-27758
8.4 HIGH

In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_netref)), a remote attacker …

Mar 12, 2024
CVE-2024-1529
7.4 HIGH

Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/adduser.php, in multiple parameters. …

Mar 12, 2024
CVE-2024-1528
7.4 HIGH

CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/moduleinterface.php, in multiple parameters. This vulnerability …

Mar 12, 2024
CVE-2024-1527
9.8 CRITICAL

Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an authenticated user to bypass the security measures of the upload …

Mar 12, 2024
CVE-2024-1304
6.3 MEDIUM

Cross-site scripting vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows a remote attacker to send a specially …

Mar 12, 2024
CVE-2024-1303
6.5 MEDIUM

Incorrectly limiting the path to a restricted directory vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows an …

Mar 12, 2024
CVE-2024-1302
7.3 HIGH

Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application's file parameter to a …

Mar 12, 2024
CVE-2024-1301
9.8 CRITICAL

SQL injection vulnerability in Badger Meter Monitool affecting versions 4.6.3 and earlier. A remote attacker could send a specially crafted SQL query to the server …

Mar 12, 2024
CVE-2024-2394
4.7 MEDIUM

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Mar 12, 2024
CVE-2024-23112
8.0 HIGH

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy …

Mar 12, 2024
CVE-2024-21761
4.3 MEDIUM

An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to download other organizations reports via …

Mar 12, 2024
CVE-2024-1618
7.8 HIGH

A search path or unquoted item vulnerability in Faronics Deep Freeze Server Standard, which affects versions 8.30.020.4627 and earlier. This vulnerability affects the DFServ.exe file. …

Mar 12, 2024
CVE-2024-1227
6.5 MEDIUM

An open redirect vulnerability, the exploitation of which could allow an attacker to create a custom URL and redirect a legitimate page to a malicious …

Mar 12, 2024
CVE-2024-1226
7.5 HIGH

The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing HTTP headers. The inclusion of invalidated data in …

Mar 12, 2024
CVE-2023-48788
9.8 CRITICAL KEV

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows …

Mar 12, 2024
CVE-2023-47534
9.6 CRITICAL

A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through …

Mar 12, 2024
CVE-2023-46717
7.5 HIGH

An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and below when configured with FortiAuthenticator in …

Mar 12, 2024
CVE-2023-42790
8.1 HIGH

A stack-based buffer overflow in Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, FortiProxy 7.4.0, 7.2.0 …

Mar 12, 2024
CVE-2023-42789
9.8 CRITICAL

A out-of-bounds write in Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, FortiProxy 7.4.0, 7.2.0 through …

Mar 12, 2024
CVE-2023-41842
6.7 MEDIUM

A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized code or commands via specially crafted command …

Mar 12, 2024
CVE-2023-36554
8.1 HIGH

A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows …

Mar 12, 2024
CVE-2024-2393
6.3 MEDIUM

A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 12, 2024
CVE-2024-2049
6.5 MEDIUM

Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the …

Mar 12, 2024
CVE-2024-28553
9.8 CRITICAL

Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the entrys parameter fromAddressNat function.

Mar 12, 2024
CVE-2024-28535
9.8 CRITICAL

Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the mitInterface parameter of fromAddressNat function.

Mar 12, 2024
CVE-2024-2391
2.4 LOW

A vulnerability was found in EVE-NG 5.0.1-13 and classified as problematic. Affected by this issue is some unknown functionality of the component Lab Handler. The …

Mar 12, 2024
CVE-2024-27907
7.8 HIGH

A vulnerability has been identified in Simcenter Femap (All versions < V2306.0000). The affected application contains an out of bounds write past the end of …

Mar 12, 2024
CVE-2024-22045
7.6 HIGH

A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.1 SP1). The product places sensitive information into files or directories that …

Mar 12, 2024
CVE-2024-22044
7.5 HIGH

A vulnerability has been identified in SENTRON 3KC ATC6 Expansion Module Ethernet (3KC9000-8TL75) (All versions). Affected devices expose an unused, unstable http service at port …

Mar 12, 2024
CVE-2024-22041
7.5 HIGH

A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN …

Mar 12, 2024
CVE-2024-22040
7.5 HIGH

A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN …

Mar 12, 2024
CVE-2024-22039
10.0 CRITICAL

A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions < IP8), Cerberus PRO EN Fire Panel FC72x IP6 (All versions < …

Mar 12, 2024
CVE-2024-21483
4.6 MEDIUM

A vulnerability has been identified in SENTRON 7KM PAC3120 AC/DC (7KM3120-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( …

Mar 12, 2024
CVE-2023-45793
5.5 MEDIUM

A vulnerability has been identified in Siveillance Control (All versions >= V2.8 < V3.1.1). The affected product does not properly check the list of access …

Mar 12, 2024
CVE-2023-41313
9.8 CRITICAL

The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 + or 1.2.8, …

Mar 12, 2024
CVE-2022-32257
9.8 CRITICAL

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application consists of a web service that lacks proper …

Mar 12, 2024
CVE-2023-4731
4.3 MEDIUM

The LadiApp plugn for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the init_endpoint() function hooked via 'init' in …

Mar 12, 2024
CVE-2023-4729
4.3 MEDIUM

The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the publish_lp() function hooked via an AJAX …

Mar 12, 2024
CVE-2023-4728
4.3 MEDIUM

The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the publish_lp() function hooked via an …

Mar 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.