CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38246
7.0 HIGH

Win32k Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38245
7.8 HIGH

Kernel Streaming Service Driver Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38244
7.8 HIGH

Kernel Streaming Service Driver Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38243
7.8 HIGH

Kernel Streaming Service Driver Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38242
7.8 HIGH

Kernel Streaming Service Driver Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38241
7.8 HIGH

Kernel Streaming Service Driver Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38240
8.1 HIGH

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38239
7.2 HIGH

Windows Kerberos Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38238
7.8 HIGH

Kernel Streaming Service Driver Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38237
7.8 HIGH

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38236
7.5 HIGH

DHCP Server Service Denial of Service Vulnerability

Sep 10, 2024
CVE-2024-38233
7.5 HIGH

Windows Networking Denial of Service Vulnerability

Sep 10, 2024
CVE-2024-38232
7.5 HIGH

Windows Networking Denial of Service Vulnerability

Sep 10, 2024
CVE-2024-38228
7.2 HIGH

Microsoft SharePoint Server Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-38227
7.2 HIGH

Microsoft SharePoint Server Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-38226
7.3 HIGH KEV

Microsoft Publisher Security Feature Bypass Vulnerability

Sep 10, 2024
CVE-2024-38225
8.8 HIGH

Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38216
8.2 HIGH

Azure Stack Hub Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38194
8.4 HIGH

An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network.

Sep 10, 2024
CVE-2024-38188
7.1 HIGH

Azure Network Watcher VM Agent Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38119
7.5 HIGH

Windows Network Address Translation (NAT) Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-38046
7.8 HIGH

PowerShell Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-38045
8.1 HIGH

Windows TCP/IP Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-38018
8.8 HIGH

Microsoft SharePoint Server Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-38014
7.8 HIGH KEV

Windows Installer Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-37980
8.8 HIGH

Microsoft SQL Server Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-37966
7.1 HIGH

Microsoft SQL Server Native Scoring Information Disclosure Vulnerability

Sep 10, 2024
CVE-2024-37965
8.8 HIGH

Microsoft SQL Server Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-37342
7.1 HIGH

Microsoft SQL Server Native Scoring Information Disclosure Vulnerability

Sep 10, 2024
CVE-2024-37341
8.8 HIGH

Microsoft SQL Server Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-37340
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-37339
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-37338
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-37337
7.1 HIGH

Microsoft SQL Server Native Scoring Information Disclosure Vulnerability

Sep 10, 2024
CVE-2024-37335
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-30073
7.8 HIGH

Windows Security Zone Mapping Security Feature Bypass Vulnerability

Sep 10, 2024
CVE-2024-26191
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-26186
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-21416
8.1 HIGH

Windows TCP/IP Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2023-6841
7.5 HIGH

A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests …

Sep 10, 2024
CVE-2024-45592
8.2 HIGH

auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Prior to version 5.2.6, there is an unescaped entity property enabling Javascript …

Sep 10, 2024
CVE-2024-45590
7.5 HIGH

body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially …

Sep 10, 2024
CVE-2024-31960
7.8 HIGH

An issue was discovered in Samsung Mobile Processor Exynos 1480, Exynos 2400. The xclipse amdgpu driver has a reference count bug. This can lead to …

Sep 10, 2024
CVE-2023-37233
8.8 HIGH

Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.

Sep 10, 2024
CVE-2023-37232
7.5 HIGH

Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.

Sep 10, 2024
CVE-2024-45044
8.8 HIGH

Bareos is open source software for backup, archiving, and recovery of data for operating systems. When a command ACL is in place and a user …

Sep 10, 2024
CVE-2024-33508
7.3 HIGH

An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow …

Sep 10, 2024
CVE-2024-23185
7.5 HIGH

Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them …

Sep 10, 2024
CVE-2024-44867
7.5 HIGH

phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.

Sep 10, 2024
CVE-2024-37728
7.5 HIGH

Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the …

Sep 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.