CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-40114
7.8 HIGH

In multiple functions of MtpFfsHandle.cpp , there is a possible out of bounds write due to a use after free. This could lead to local …

Feb 15, 2024
CVE-2023-40113
5.5 MEDIUM

In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could lead to …

Feb 15, 2024
CVE-2023-40112
5.5 MEDIUM

In ippSetValueTag of ipp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Feb 15, 2024
CVE-2023-40111
7.8 HIGH

In setMediaButtonReceiver of MediaSessionRecord.java, there is a possible way to send a pending intent on behalf of system_server due to a confused deputy. This could …

Feb 15, 2024
CVE-2023-40110
7.8 HIGH

In multiple functions of MtpPacket.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation …

Feb 15, 2024
CVE-2023-40109
7.8 HIGH

In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass. This could lead to local escalation of privilege …

Feb 15, 2024
CVE-2023-40107
7.8 HIGH

In ARTPWriter of ARTPWriter.cpp, there is a possible use after free due to uninitialized data. This could lead to local escalation of privilege with no …

Feb 15, 2024
CVE-2023-40106
7.8 HIGH

In sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local …

Feb 15, 2024
CVE-2023-40105
5.5 MEDIUM

In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could lead to local information …

Feb 15, 2024
CVE-2023-40104
7.5 HIGH

In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This could lead to remote information disclosure with …

Feb 15, 2024
CVE-2023-40100
7.8 HIGH

In discovery_thread of Dns64Configuration.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with …

Feb 15, 2024
CVE-2024-25123
7.3 HIGH

MSS (Mission Support System) is an open source package designed for planning atmospheric research flights. In file: `index.py`, there is a method that is vulnerable …

Feb 15, 2024
CVE-2024-23479
9.6 CRITICAL

SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated …

Feb 15, 2024
CVE-2024-23478
8.0 HIGH

SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to …

Feb 15, 2024
CVE-2024-23477
7.9 HIGH

The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an …

Feb 15, 2024
CVE-2024-23476
9.6 CRITICAL

The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an …

Feb 15, 2024
CVE-2024-21728
6.1 MEDIUM

An Open Redirect vulnerability was found in osTicky2 below 2.2.8. osTicky (osTicket Bridge) by SmartCalc is a Joomla 3.x extension that provides Joomla fronted integration …

Feb 15, 2024
CVE-2024-0622
8.8 HIGH

Local privilege escalation vulnerability affects OpenText Operations Agent product versions 12.15 and 12.20-12.25 when installed on Non-Windows platforms. The vulnerability could allow local privilege escalation.

Feb 15, 2024
CVE-2024-0240
6.5 MEDIUM

A memory leak in the Silicon Labs' Bluetooth stack for EFR32 products may cause memory to be exhausted when sending notifications to multiple clients, this …

Feb 15, 2024
CVE-2023-6123
7.5 HIGH

Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could result in a remote code execution attack.

Feb 15, 2024
CVE-2023-40057
9.0 CRITICAL

The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to …

Feb 15, 2024
CVE-2024-25502
9.8 CRITICAL

Directory Traversal vulnerability in flusity CMS v.2.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via the download_backup.php component.

Feb 15, 2024
CVE-2024-25373
4.6 MEDIUM

Tenda AC10V4.0 V16.03.10.20 was discovered to contain a stack overflow via the page parameter in the sub_49B384 function.

Feb 15, 2024
CVE-2023-6937
5.3 MEDIUM

wolfSSL prior to 5.6.6 did not check that messages in one (D)TLS record do not span key boundaries. As a result, it was possible to …

Feb 15, 2024
CVE-2023-7081
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in POSTAHSİL Online Payment System allows SQL Injection.This issue affects Online Payment …

Feb 15, 2024
CVE-2023-6255
7.5 HIGH

Use of Hard-coded Credentials vulnerability in Utarit Information Technologies SoliPay Mobile App allows Read Sensitive Strings Within an Executable.This issue affects SoliPay Mobile App: before …

Feb 15, 2024
CVE-2023-5155
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies SoliPay Mobile App allows SQL Injection.This issue affects …

Feb 15, 2024
CVE-2023-4993
7.5 HIGH

Incorrect Use of Privileged APIs vulnerability in Utarit Information Technologies SoliPay Mobile App allows Collect Data as Provided by Users.This issue affects SoliPay Mobile App: …

Feb 15, 2024
CVE-2024-23113
9.8 CRITICAL KEV

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 …

Feb 15, 2024
CVE-2024-20720
9.1 CRITICAL

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') …

Feb 15, 2024
CVE-2024-20719
9.1 CRITICAL

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker …

Feb 15, 2024
CVE-2024-20718
4.3 MEDIUM

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. …

Feb 15, 2024
CVE-2024-20717
5.4 MEDIUM

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker …

Feb 15, 2024
CVE-2024-20716
4.9 MEDIUM

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to an application denial-of-service. A high-privileged …

Feb 15, 2024
CVE-2023-47537
4.8 MEDIUM

An improper certificate validation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.6, FortiOS 7.0.0 through 7.0.15, FortiOS 6.4 all versions allows a …

Feb 15, 2024
CVE-2023-45581
8.8 HIGH

An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site administrator with Super Admin privileges to …

Feb 15, 2024
CVE-2023-44253
5.0 MEDIUM

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through …

Feb 15, 2024
CVE-2023-26206
6.8 MEDIUM

An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC 9.4.0 - 9.4.2, 9.2.0 - 9.2.8, 9.1.0 - 9.1.10 and 7.2.0 …

Feb 15, 2024
CVE-2024-20750
7.8 HIGH

Substance3D - Designer versions 13.1.0 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read …

Feb 15, 2024
CVE-2024-20749
5.5 MEDIUM

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024
CVE-2024-20748
5.5 MEDIUM

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024
CVE-2024-20747
5.5 MEDIUM

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024
CVE-2024-20739
7.8 HIGH

Audition versions 24.0.3, 23.6.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2024-20738
9.8 CRITICAL

Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker …

Feb 15, 2024
CVE-2024-20736
5.5 MEDIUM

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024
CVE-2024-20735
5.5 MEDIUM

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024
CVE-2024-20734
5.5 MEDIUM

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker …

Feb 15, 2024
CVE-2024-20733
5.5 MEDIUM

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an Improper Input Validation vulnerability that could lead to an application denial-of-service. An attacker could …

Feb 15, 2024
CVE-2024-20731
7.8 HIGH

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Feb 15, 2024
CVE-2024-20730
7.8 HIGH

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the …

Feb 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.