CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21782
6.7 MEDIUM

BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced shell …

Feb 14, 2024
CVE-2024-21771
7.5 HIGH

For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic against signatures, resulting in Traffic Management Microkernel …

Feb 14, 2024
CVE-2024-21763
7.5 HIGH

When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclosed queries can cause the Traffic Management …

Feb 14, 2024
CVE-2024-0568
8.8 HIGH

CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering of device configuration over NFC communication.

Feb 14, 2024
CVE-2023-6409
7.7 HIGH

CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application password when opening the file with …

Feb 14, 2024
CVE-2023-6408
8.1 HIGH

CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, …

Feb 14, 2024
CVE-2023-52399

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-52398

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-52396

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-52395

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-52392

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-51755

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-51754

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-50337

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-50336

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-50335

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-50329

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-50293

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-50241

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-50174

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-50170

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-49872

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-49870

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-49811

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-49712

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-49710

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-49611

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-49609

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-49590

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-49588

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-48734

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-48729

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-45850

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-45738

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-45224

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-43749

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-42775

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-42665

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-42437

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-39450

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-38262

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-38137

Rejected reason: This is unused.

Feb 14, 2024
CVE-2023-27975
7.1 HIGH

CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with …

Feb 14, 2024
CVE-2023-50868
7.5 HIGH

The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial …

Feb 14, 2024
CVE-2023-50387
7.5 HIGH

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service …

Feb 14, 2024
CVE-2024-25226
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected …

Feb 14, 2024
CVE-2024-25225
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected …

Feb 14, 2024
CVE-2024-25224
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected …

Feb 14, 2024
CVE-2024-25223
9.8 CRITICAL

Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminView/viewEachOrder.php.

Feb 14, 2024
CVE-2024-25222
9.8 CRITICAL

Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManager/EditProject.php.

Feb 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.