CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-24696
6.8 MEDIUM

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user …

Feb 14, 2024
CVE-2024-24695
6.8 MEDIUM

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user …

Feb 14, 2024
CVE-2024-24691
9.6 CRITICAL

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user …

Feb 14, 2024
CVE-2024-24690
5.4 MEDIUM

Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.

Feb 14, 2024
CVE-2024-1485
8.0 HIGH

A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing …

Feb 14, 2024
CVE-2024-25121
7.1 HIGH

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File …

Feb 13, 2024
CVE-2024-25120
4.3 MEDIUM

TYPO3 is an open source PHP based web content management system released under the GNU GPL. The TYPO3-specific `t3://` URI scheme could be used to …

Feb 13, 2024
CVE-2024-25119
4.9 MEDIUM

TYPO3 is an open source PHP based web content management system released under the GNU GPL. The plaintext value of `$GLOBALS['SYS']['encryptionKey']` was displayed in the …

Feb 13, 2024
CVE-2024-25118
4.3 MEDIUM

TYPO3 is an open source PHP based web content management system released under the GNU GPL. Password hashes were being reflected in the editing forms …

Feb 13, 2024
CVE-2023-38960
7.3 HIGH

Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain privileges and execute arbitrary code via crafted executable …

Feb 13, 2024
CVE-2023-6152
5.4 MEDIUM

A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only …

Feb 13, 2024
CVE-2024-24142
9.8 CRITICAL

Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.

Feb 13, 2024
CVE-2023-31347
4.9 MEDIUM

Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC …

Feb 13, 2024
CVE-2023-31346
6.0 MEDIUM

Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.

Feb 13, 2024
CVE-2023-20587
7.1 HIGH

Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution.

Feb 13, 2024
CVE-2023-20579
6.0 MEDIUM

Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in …

Feb 13, 2024
CVE-2021-46757
7.8 HIGH

Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel …

Feb 13, 2024
CVE-2024-25122
7.1 HIGH

sidekiq-unique-jobs is an open source project which prevents simultaneous Sidekiq jobs with the same unique arguments to run. Specially crafted GET request parameters handled by …

Feb 13, 2024
CVE-2024-24814
7.5 HIGH

mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected …

Feb 13, 2024
CVE-2024-24751
4.3 MEDIUM

sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access control check …

Feb 13, 2024
CVE-2024-1378
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1374
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1372
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1369
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1359
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1355
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1354
8.0 HIGH

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1216

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 13, 2024
CVE-2024-1084
6.5 MEDIUM

Cross-site Scripting in the tag name pattern field in the tag protections UI in GitHub Enterprise Server allows a malicious website that requires user interaction …

Feb 13, 2024
CVE-2024-1082
6.3 MEDIUM

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker to gain unauthorized read permission to files by deploying arbitrary symbolic …

Feb 13, 2024
CVE-2024-21420
8.8 HIGH

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2024-21413
9.8 CRITICAL KEV

Microsoft Outlook Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2024-21412
8.1 HIGH KEV

Internet Shortcut Files Security Feature Bypass Vulnerability

Feb 13, 2024
CVE-2024-21410
9.8 CRITICAL KEV

Microsoft Exchange Server Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-21406
7.5 HIGH

Windows Printing Service Spoofing Vulnerability

Feb 13, 2024
CVE-2024-21405
7.0 HIGH

Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-21404
7.5 HIGH

.NET Denial of Service Vulnerability

Feb 13, 2024
CVE-2024-21403
9.0 CRITICAL

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-21402
7.1 HIGH

Microsoft Outlook Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-21401
9.8 CRITICAL

Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-21397
5.3 MEDIUM

Microsoft Azure File Sync Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-21396
7.6 HIGH

Dynamics 365 Sales Spoofing Vulnerability

Feb 13, 2024
CVE-2024-21395
8.2 HIGH

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

Feb 13, 2024
CVE-2024-21394
7.6 HIGH

Dynamics 365 Field Service Spoofing Vulnerability

Feb 13, 2024
CVE-2024-21393
7.6 HIGH

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

Feb 13, 2024
CVE-2024-21391
8.8 HIGH

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2024-21389
7.6 HIGH

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

Feb 13, 2024
CVE-2024-21386
7.5 HIGH

.NET Denial of Service Vulnerability

Feb 13, 2024
CVE-2024-21384
7.8 HIGH

Microsoft Office OneNote Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2024-21381
6.8 MEDIUM

Microsoft Azure Active Directory B2C Spoofing Vulnerability

Feb 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.