CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23784
6.5 MEDIUM

Improper access control vulnerability exists in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier, which may allow a network-adjacent unauthenticated attacker to …

Feb 14, 2024
CVE-2024-23783
8.8 HIGH

Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to access the affected product …

Feb 14, 2024
CVE-2023-48987
7.5 HIGH

Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, …

Feb 14, 2024
CVE-2023-48986
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate …

Feb 14, 2024
CVE-2023-48985
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate …

Feb 14, 2024
CVE-2023-44294
5.4 MEDIUM

In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user …

Feb 14, 2024
CVE-2023-44293
5.4 MEDIUM

In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user …

Feb 14, 2024
CVE-2023-44283
7.8 HIGH

In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4.1), a security concern has been identified, …

Feb 14, 2024
CVE-2023-39249
6.3 MEDIUM

Dell SupportAssist for Business PCs version 3.4.0 contains a local Authentication Bypass vulnerability that allows locally authenticated non-admin users to gain temporary privilege within the …

Feb 14, 2024
CVE-2023-25535
7.2 HIGH

Dell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has a high vulnerability that can result in local …

Feb 14, 2024
CVE-2024-22455
4.4 MEDIUM

Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with local access could potentially exploit …

Feb 14, 2024
CVE-2024-25125
5.3 MEDIUM

Digdag is an open source tool that to build, run, schedule, and monitor complex pipelines of tasks across various platforms. Treasure Data's digdag workload automation …

Feb 14, 2024
CVE-2024-24699
6.5 MEDIUM

Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.

Feb 14, 2024
CVE-2024-24698
4.9 MEDIUM

Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.

Feb 14, 2024
CVE-2024-24697
7.2 HIGH

Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access.

Feb 14, 2024
CVE-2024-24696
6.8 MEDIUM

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user …

Feb 14, 2024
CVE-2024-24695
6.8 MEDIUM

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user …

Feb 14, 2024
CVE-2024-24691
9.6 CRITICAL

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user …

Feb 14, 2024
CVE-2024-24690
5.4 MEDIUM

Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.

Feb 14, 2024
CVE-2024-1485
8.0 HIGH

A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing …

Feb 14, 2024
CVE-2024-25121
7.1 HIGH

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File …

Feb 13, 2024
CVE-2024-25120
4.3 MEDIUM

TYPO3 is an open source PHP based web content management system released under the GNU GPL. The TYPO3-specific `t3://` URI scheme could be used to …

Feb 13, 2024
CVE-2024-25119
4.9 MEDIUM

TYPO3 is an open source PHP based web content management system released under the GNU GPL. The plaintext value of `$GLOBALS['SYS']['encryptionKey']` was displayed in the …

Feb 13, 2024
CVE-2024-25118
4.3 MEDIUM

TYPO3 is an open source PHP based web content management system released under the GNU GPL. Password hashes were being reflected in the editing forms …

Feb 13, 2024
CVE-2023-38960
7.3 HIGH

Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain privileges and execute arbitrary code via crafted executable …

Feb 13, 2024
CVE-2023-6152
5.4 MEDIUM

A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only …

Feb 13, 2024
CVE-2024-24142
9.8 CRITICAL

Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.

Feb 13, 2024
CVE-2023-31347
4.9 MEDIUM

Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC …

Feb 13, 2024
CVE-2023-31346
6.0 MEDIUM

Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.

Feb 13, 2024
CVE-2023-20587
7.1 HIGH

Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution.

Feb 13, 2024
CVE-2023-20579
6.0 MEDIUM

Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in …

Feb 13, 2024
CVE-2021-46757
7.8 HIGH

Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel …

Feb 13, 2024
CVE-2024-25122
7.1 HIGH

sidekiq-unique-jobs is an open source project which prevents simultaneous Sidekiq jobs with the same unique arguments to run. Specially crafted GET request parameters handled by …

Feb 13, 2024
CVE-2024-24814
7.5 HIGH

mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected …

Feb 13, 2024
CVE-2024-24751
4.3 MEDIUM

sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access control check …

Feb 13, 2024
CVE-2024-1378
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1374
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1372
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1369
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1359
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1355
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1354
8.0 HIGH

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1216

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 13, 2024
CVE-2024-1084
6.5 MEDIUM

Cross-site Scripting in the tag name pattern field in the tag protections UI in GitHub Enterprise Server allows a malicious website that requires user interaction …

Feb 13, 2024
CVE-2024-1082
6.3 MEDIUM

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker to gain unauthorized read permission to files by deploying arbitrary symbolic …

Feb 13, 2024
CVE-2024-21420
8.8 HIGH

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2024-21413
9.8 CRITICAL KEV

Microsoft Outlook Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2024-21412
8.1 HIGH KEV

Internet Shortcut Files Security Feature Bypass Vulnerability

Feb 13, 2024
CVE-2024-21410
9.8 CRITICAL KEV

Microsoft Exchange Server Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-21406
7.5 HIGH

Windows Printing Service Spoofing Vulnerability

Feb 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.