CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20673
7.8 HIGH

Microsoft Office Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2024-20667
7.5 HIGH

Azure DevOps Server Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2023-50808
6.1 MEDIUM

Zimbra Collaboration before Kepler 9.0.0 Patch 38 GA allows DOM-based JavaScript injection in the Modern UI.

Feb 13, 2024
CVE-2023-20570
3.3 LOW

Insufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentially load arbitrary bitstreams.

Feb 13, 2024
CVE-2024-22923
9.8 CRITICAL

SQL injection vulnerability in adv radius v.2.2.5 allows a local attacker to execute arbitrary code via a crafted script.

Feb 13, 2024
CVE-2023-48432
6.1 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. XSS, with resultant session stealing, can occur via JavaScript code in a link …

Feb 13, 2024
CVE-2023-45207
6.1 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. An attacker can send a PDF document through mail that contains malicious JavaScript. …

Feb 13, 2024
CVE-2023-45206
6.1 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. Through the help document endpoint in webmail, an attacker can inject JavaScript or …

Feb 13, 2024
CVE-2023-26562
6.5 MEDIUM

In Zimbra Collaboration (ZCS) 8.8.15 and 9.0, a closed account (with 2FA and generated passwords) can send e-mail messages when configured for Imap/smtp.

Feb 13, 2024
CVE-2024-23440
7.1 HIGH

Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability. The 0x22200B IOCTL code of the Vba32m64.sys driver allows to read up to 0x802 …

Feb 13, 2024
CVE-2024-23439
7.1 HIGH

Vba32 Antivirus v3.36.0 is vulnerable to an Arbitrary Memory Read vulnerability by triggering the 0x22201B, 0x22201F, 0x222023, 0x222027 ,0x22202B, 0x22202F, 0x22203F, 0x222057 and 0x22205B IOCTL …

Feb 13, 2024
CVE-2024-1163
7.1 HIGH

The attacker may exploit a path traversal vulnerability leading to information disclosure.

Feb 13, 2024
CVE-2024-1140
6.1 MEDIUM

Twister Antivirus v8.17 is vulnerable to an Out-of-bounds Read vulnerability by triggering the 0x801120B8 IOCTL code of the filmfd.sys driver.

Feb 13, 2024
CVE-2024-1096
5.5 MEDIUM

Twister Antivirus v8.17 is vulnerable to a Denial of Service vulnerability by triggering the 0x80112067, 0x801120CB 0x801120CC 0x80112044, 0x8011204B, 0x8011204F, 0x80112057, 0x8011205B, 0x8011205F, 0x80112063, 0x8011206F, …

Feb 13, 2024
CVE-2024-24782
4.3 MEDIUM

An unauthenticated attacker can send a ping request from one network to another through an error in the origin verification even though the ports are …

Feb 13, 2024
CVE-2024-24781
7.5 HIGH

An unauthenticated remote attacker can use an uncontrolled resource consumption vulnerability to DoS the affected devices through excessive traffic on a single ethernet port.

Feb 13, 2024
CVE-2024-1309
6.5 MEDIUM

Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niagara Framework: before Niagara AX 3.8.1, before Niagara …

Feb 13, 2024
CVE-2024-0707

Rejected reason: **REJECT** Not a valid vulnerability.

Feb 13, 2024
CVE-2023-6516
7.5 HIGH

To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some …

Feb 13, 2024
CVE-2023-5680
5.3 MEDIUM

If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node …

Feb 13, 2024
CVE-2023-5679
7.5 HIGH

A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are …

Feb 13, 2024
CVE-2023-5517
7.5 HIGH

A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redirect <domain>;` is configured, and - the resolver …

Feb 13, 2024
CVE-2023-4408
7.5 HIGH

The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, …

Feb 13, 2024
CVE-2024-1160
5.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Link in all versions up to, and including, …

Feb 13, 2024
CVE-2024-1159
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.8.0 …

Feb 13, 2024
CVE-2024-1157
5.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button URL in all versions up to, and including, …

Feb 13, 2024
CVE-2023-6072
4.6 MEDIUM

A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing arbitrary …

Feb 13, 2024
CVE-2024-24925
7.8 HIGH

A vulnerability has been identified in Simcenter Femap (All versions < V2306.0000). The affected application is vulnerable to uninitialized pointer access while parsing specially crafted …

Feb 13, 2024
CVE-2024-24924
7.8 HIGH

A vulnerability has been identified in Simcenter Femap (All versions < V2306.0000). The affected application contains an out of bounds write past the end of …

Feb 13, 2024
CVE-2024-24923
7.8 HIGH

A vulnerability has been identified in Simcenter Femap (All versions < V2401.0000), Simcenter Femap (All versions < V2306.0001). The affected applications contain an out of …

Feb 13, 2024
CVE-2024-24922
7.8 HIGH

A vulnerability has been identified in Simcenter Femap (All versions < V2401.0000). The affected application contains an out of bounds write past the end of …

Feb 13, 2024
CVE-2024-24921
7.8 HIGH

A vulnerability has been identified in Simcenter Femap (All versions < V2401.0000). The affected application is vulnerable to memory corruption while parsing specially crafted Catia …

Feb 13, 2024
CVE-2024-24920
7.8 HIGH

A vulnerability has been identified in Simcenter Femap (All versions < V2401.0000). The affected application contains an out of bounds write past the end of …

Feb 13, 2024
CVE-2024-23816
9.8 CRITICAL

A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpetual Medium (9DE5110-8CA12-1AX0) (All versions < V4.3), Location …

Feb 13, 2024
CVE-2024-23813
7.3 HIGH

A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector of the affected product lacks proper authentication. …

Feb 13, 2024
CVE-2024-23812
8.0 HIGH

A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application incorrectly neutralizes special elements when creating a report which …

Feb 13, 2024
CVE-2024-23811
8.8 HIGH

A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application allows users to upload arbitrary files via TFTP. This …

Feb 13, 2024
CVE-2024-23810
8.8 HIGH

A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application is vulnerable to SQL injection. This could allow an …

Feb 13, 2024
CVE-2024-23804
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (All versions < V2302.0006). The affected applications …

Feb 13, 2024
CVE-2024-23803
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V2302 (All versions < V2302.0007). The affected application contains an …

Feb 13, 2024
CVE-2024-23802
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (All versions < V2302.0006). The affected applications …

Feb 13, 2024
CVE-2024-23801
3.3 LOW

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V2302 (All versions < V2302.0007). The affected applications contain a …

Feb 13, 2024
CVE-2024-23800
3.3 LOW

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V2302 (All versions < V2302.0007). The affected applications contain a …

Feb 13, 2024
CVE-2024-23799
3.3 LOW

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V2302 (All versions < V2302.0007). The affected applications contain a …

Feb 13, 2024
CVE-2024-23798
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (All versions < V2302.0006). The affected applications …

Feb 13, 2024
CVE-2024-23797
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (All versions < V2302.0006). The affected applications …

Feb 13, 2024
CVE-2024-23796
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (All versions < V2302.0006). The affected application …

Feb 13, 2024
CVE-2024-23795
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (All versions < V2302.0006). The affected application …

Feb 13, 2024
CVE-2024-22043
3.3 LOW

A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.251), Parasolid V35.1 (All versions < V35.1.170). The affected applications contain a null pointer …

Feb 13, 2024
CVE-2024-22042
7.8 HIGH

A vulnerability has been identified in Unicam FX (All versions). The windows installer agent used in affected product contains incorrect use of privileged APIs that …

Feb 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.