CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20656
7.8 HIGH

Visual Studio Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-20655
6.6 MEDIUM

Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-20654
8.0 HIGH

Microsoft ODBC Driver Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-20653
7.8 HIGH

Microsoft Common Log File System Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-20652
8.1 HIGH

Windows HTML Platforms Security Feature Bypass Vulnerability

Jan 9, 2024
CVE-2024-0340
4.4 MEDIUM

A vulnerability was found in vhost_new_msg in drivers/vhost/vhost.c in the Linux kernel, which does not properly initialize memory in messages passed between virtual guests and …

Jan 9, 2024
CVE-2024-0226
4.8 MEDIUM

Synopsys Seeker versions prior to 2023.12.0 are vulnerable to a stored cross-site scripting vulnerability through a specially crafted payload.

Jan 9, 2024
CVE-2024-0057
9.1 CRITICAL

NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability

Jan 9, 2024
CVE-2024-0056
8.7 HIGH

Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability

Jan 9, 2024
CVE-2022-48618
7.0 HIGH KEV

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An …

Jan 9, 2024
CVE-2024-22165
6.5 MEDIUM

In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perform a denial of service (DoS). The malformed …

Jan 9, 2024
CVE-2024-22164
4.3 MEDIUM

In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a denial of service (DoS) to the Investigation. The …

Jan 9, 2024
CVE-2024-0228

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is a duplicate of CVE-2024-0193.

Jan 9, 2024
CVE-2023-6129
6.5 MEDIUM

Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications running on PowerPC CPU based …

Jan 9, 2024
CVE-2023-7223
5.3 MEDIUM

A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This affects an unknown part of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Jan 9, 2024
CVE-2023-7222
7.2 HIGH

A vulnerability was found in Totolink X2000R 1.0.0-B20221212.1452. It has been declared as critical. This vulnerability affects the function formTmultiAP of the file /bin/boa of …

Jan 9, 2024
CVE-2022-36765
7.0 HIGH

EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. …

Jan 9, 2024
CVE-2022-36764
7.0 HIGH

EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation …

Jan 9, 2024
CVE-2022-36763
7.0 HIGH

EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation …

Jan 9, 2024
CVE-2024-0213
8.2 HIGH

A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause …

Jan 9, 2024
CVE-2024-0206
7.1 HIGH

A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation …

Jan 9, 2024
CVE-2023-7221
9.8 CRITICAL

A vulnerability was found in Totolink T6 4.1.9cu.5241_B20210923. It has been classified as critical. This affects the function main of the file /cgi-bin/cstecgi.cgi?action=login of the …

Jan 9, 2024
CVE-2022-28975
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Jan 9, 2024
CVE-2024-22370
4.6 MEDIUM

In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible

Jan 9, 2024
CVE-2023-5376
8.6 HIGH

An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware version 2024/01.

Jan 9, 2024
CVE-2023-5347
9.8 CRITICAL

An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This …

Jan 9, 2024
CVE-2023-51746
7.8 HIGH

A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), Teamcenter Visualization V14.1 (All versions < V14.1.0.12), …

Jan 9, 2024
CVE-2023-51745
7.8 HIGH

A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), Teamcenter Visualization V14.1 (All versions < V14.1.0.12), …

Jan 9, 2024
CVE-2023-51744
3.3 LOW

A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), Teamcenter Visualization V14.1 (All versions < V14.1.0.12), …

Jan 9, 2024
CVE-2023-51439
7.8 HIGH

A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), Teamcenter Visualization V14.1 (All versions < V14.1.0.12), …

Jan 9, 2024
CVE-2023-51438
10.0 CRITICAL

A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC647E (All versions with maxView Storage …

Jan 9, 2024
CVE-2023-49722
8.3 HIGH

Network port 8899 open in WiFi firmware of BCC101/BCC102/BCC50 products, that allows an attacker to connect to the device via same WiFi network.

Jan 9, 2024
CVE-2023-49621
9.8 CRITICAL

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application uses default credential …

Jan 9, 2024
CVE-2023-49252
7.5 HIGH

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The affected application allows IP configuration change without authentication to the device. …

Jan 9, 2024
CVE-2023-49251
8.8 HIGH

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application allows an attacker …

Jan 9, 2024
CVE-2023-49132
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to uninitialized pointer access while …

Jan 9, 2024
CVE-2023-49131
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to uninitialized pointer access while …

Jan 9, 2024
CVE-2023-49130
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to uninitialized pointer access while …

Jan 9, 2024
CVE-2023-49129
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected applications contain a stack overflow vulnerability while parsing …

Jan 9, 2024
CVE-2023-49128
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application contains an out of bounds write past …

Jan 9, 2024
CVE-2023-49127
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected applications contain an out of bounds read past …

Jan 9, 2024
CVE-2023-49126
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected applications contain an out of bounds read past …

Jan 9, 2024
CVE-2023-49124
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected applications contain an out of bounds read past …

Jan 9, 2024
CVE-2023-49123
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while …

Jan 9, 2024
CVE-2023-49122
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while …

Jan 9, 2024
CVE-2023-49121
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while …

Jan 9, 2024
CVE-2023-44120
7.8 HIGH

A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q4). The affected product's sudo configuration permits the local administrative account to execute …

Jan 9, 2024
CVE-2023-42797
6.6 MEDIUM

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.20), CP-8050 MASTER MODULE (All versions < CPCI85 V05.20). The network configuration …

Jan 9, 2024
CVE-2024-22368
5.5 MEDIUM

The Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a crafted XLSX document. This occurs because the memoize implementation …

Jan 9, 2024
CVE-2023-6149
5.7 MEDIUM

Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, which was missing a permission …

Jan 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.