CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1367
7.2 HIGH

A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead …

Feb 14, 2024
CVE-2023-49721
6.7 MEDIUM

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

Feb 14, 2024
CVE-2023-48733
6.7 MEDIUM

An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.

Feb 14, 2024
CVE-2024-25619
3.1 LOW

Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the streaming server wasn't being informed that the …

Feb 14, 2024
CVE-2024-25618
4.2 MEDIUM

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configured authentication providers (CAS, SAML, OIDC) to attach to …

Feb 14, 2024
CVE-2024-25617
5.3 MEDIUM

Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value …

Feb 14, 2024
CVE-2024-25165
7.8 HIGH

A global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex.

Feb 14, 2024
CVE-2024-1482
7.1 HIGH

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create new branches in public repositories and run arbitrary GitHub …

Feb 14, 2024
CVE-2023-50927
8.6 HIGH

Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An attacker can trigger out-of-bounds reads in the RPL-Lite implementation of the RPL protocol …

Feb 14, 2024
CVE-2023-50926
7.5 HIGH

Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds read can be caused by an incoming DIO message when using the …

Feb 14, 2024
CVE-2024-25301
7.2 HIGH

Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php.

Feb 14, 2024
CVE-2024-25300
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in Redaxo v5.15.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Feb 14, 2024
CVE-2023-48229
7.0 HIGH

Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds write exists in the driver for IEEE 802.15.4 radios on nRF platforms …

Feb 14, 2024
CVE-2024-0011
4.3 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context …

Feb 14, 2024
CVE-2024-0010
4.3 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context …

Feb 14, 2024
CVE-2024-0009
6.3 MEDIUM

An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a …

Feb 14, 2024
CVE-2024-0008
6.6 MEDIUM

Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.

Feb 14, 2024
CVE-2024-0007
6.8 MEDIUM

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web …

Feb 14, 2024
CVE-2024-24990
7.5 HIGH

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The …

Feb 14, 2024
CVE-2024-24989
7.5 HIGH

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The …

Feb 14, 2024
CVE-2024-24966
6.2 MEDIUM

When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized. Note: Software versions which have reached …

Feb 14, 2024
CVE-2024-24775
7.5 HIGH

When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. …

Feb 14, 2024
CVE-2024-23982
7.5 HIGH

When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This …

Feb 14, 2024
CVE-2024-23979
7.5 HIGH

When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an …

Feb 14, 2024
CVE-2024-23976
6.0 MEDIUM

When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing iAppsLX templates on a …

Feb 14, 2024
CVE-2024-23805
7.5 HIGH

Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility and Reporting module, this may occur when the HTTP Analytics …

Feb 14, 2024
CVE-2024-23607
5.5 MEDIUM

A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView directory. Note: Software versions …

Feb 14, 2024
CVE-2024-23603
3.8 LOW

An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) …

Feb 14, 2024
CVE-2024-23314
7.5 HIGH

When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions …

Feb 14, 2024
CVE-2024-23308
7.5 HIGH

When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause …

Feb 14, 2024
CVE-2024-23306
7.1 HIGH

A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files. Note: Software versions which have reached End …

Feb 14, 2024
CVE-2024-22389
7.2 HIGH

When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. …

Feb 14, 2024
CVE-2024-22093
8.7 HIGH

When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can …

Feb 14, 2024
CVE-2024-21849
7.5 HIGH

When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) …

Feb 14, 2024
CVE-2024-21789
7.5 HIGH

When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software …

Feb 14, 2024
CVE-2024-21782
6.7 MEDIUM

BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced shell …

Feb 14, 2024
CVE-2024-21771
7.5 HIGH

For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic against signatures, resulting in Traffic Management Microkernel …

Feb 14, 2024
CVE-2024-21763
7.5 HIGH

When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclosed queries can cause the Traffic Management …

Feb 14, 2024
CVE-2024-0568
8.8 HIGH

CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering of device configuration over NFC communication.

Feb 14, 2024
CVE-2023-6409
7.7 HIGH

CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application password when opening the file with …

Feb 14, 2024
CVE-2023-6408
8.1 HIGH

CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, …

Feb 14, 2024
CVE-2023-52399

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-52398

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-52396

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-52395

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-52392

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-51755

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-51754

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-50337

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-50336

Rejected reason: This is unused.

Feb 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.