CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-6255
7.5 HIGH

Use of Hard-coded Credentials vulnerability in Utarit Information Technologies SoliPay Mobile App allows Read Sensitive Strings Within an Executable.This issue affects SoliPay Mobile App: before …

Feb 15, 2024
CVE-2023-4993
7.5 HIGH

Incorrect Use of Privileged APIs vulnerability in Utarit Information Technologies SoliPay Mobile App allows Collect Data as Provided by Users.This issue affects SoliPay Mobile App: …

Feb 15, 2024
CVE-2023-45581
8.8 HIGH

An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site administrator with Super Admin privileges to …

Feb 15, 2024
CVE-2024-20750
7.8 HIGH

Substance3D - Designer versions 13.1.0 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read …

Feb 15, 2024
CVE-2024-20739
7.8 HIGH

Audition versions 24.0.3, 23.6.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2024-20731
7.8 HIGH

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Feb 15, 2024
CVE-2024-20730
7.8 HIGH

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the …

Feb 15, 2024
CVE-2024-20729
7.8 HIGH

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Feb 15, 2024
CVE-2024-20728
7.8 HIGH

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2024-20727
7.8 HIGH

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2024-20726
7.8 HIGH

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2023-39244
7.3 HIGH

DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit …

Feb 15, 2024
CVE-2024-20744
7.8 HIGH

Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2024-20743
7.8 HIGH

Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2024-20742
7.8 HIGH

Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read …

Feb 15, 2024
CVE-2024-20741
7.8 HIGH

Substance3D - Painter versions 9.1.1 and earlier are affected by a Write-what-where Condition vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2024-20740
7.8 HIGH

Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2024-20723
7.8 HIGH

Substance3D - Painter versions 9.1.1 and earlier are affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2023-4539
7.5 HIGH

Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensitive data stored …

Feb 15, 2024
CVE-2023-4537
7.4 HIGH

Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to …

Feb 15, 2024
CVE-2024-24386
7.2 HIGH

An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalpbx/scripts folder.

Feb 15, 2024
CVE-2024-0353
7.8 HIGH

Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.

Feb 15, 2024
CVE-2023-51787
7.5 HIGH

An issue was discovered in Wind River VxWorks 7 22.09 and 23.03. If a VxWorks task or POSIX thread that uses OpenSSL exits, limited per-task …

Feb 15, 2024
CVE-2022-23092
8.8 HIGH

The implementation of lib9p's handling of RWALK messages was missing a bounds check needed when unpacking the message contents. The missing check means that the …

Feb 15, 2024
CVE-2022-23090
7.7 HIGH

The aio_aqueue function, used by the lio_listio system call, fails to release a reference to a credential in an error case. An attacker may cause …

Feb 15, 2024
CVE-2024-1488
8.0 HIGH

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If …

Feb 15, 2024
CVE-2022-23087
8.8 HIGH

The e1000 network adapters permit a variety of modifications to an Ethernet packet when it is being transmitted. These include the insertion of IP and …

Feb 15, 2024
CVE-2022-23086
7.8 HIGH

Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it …

Feb 15, 2024
CVE-2022-23085
8.2 HIGH

A user-provided integer option was passed to nmreq_copyin() without checking if it would overflow. This insufficient bounds checking could lead to kernel memory corruption. On …

Feb 15, 2024
CVE-2022-23084
7.5 HIGH

The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This time-of-check to time-of-use bug could lead …

Feb 15, 2024
CVE-2024-26262
8.8 HIGH

EBM Technologies Uniweb/SoliPACS WebServer's query functionality lacks proper restrictions of user input, allowing remote attackers authenticated as regular user to inject SQL commands for reading, …

Feb 15, 2024
CVE-2024-1523
8.8 HIGH

EC-WEB FS-EZViewer(Web)'s query functionality lacks proper restrictions of user input, allowing remote attackers authenticated as regular user to inject SQL commands for reading, modifying, and …

Feb 15, 2024
CVE-2024-24301
8.8 HIGH

Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell …

Feb 14, 2024
CVE-2023-6138
7.9 HIGH

A potential security vulnerability has been identified in the system BIOS for certain HP Workstation PCs, which might allow escalation of privilege, arbitrary code execution, …

Feb 14, 2024
CVE-2024-1367
7.2 HIGH

A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead …

Feb 14, 2024
CVE-2024-25165
7.8 HIGH

A global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex.

Feb 14, 2024
CVE-2024-1482
7.1 HIGH

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create new branches in public repositories and run arbitrary GitHub …

Feb 14, 2024
CVE-2023-50927
8.6 HIGH

Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An attacker can trigger out-of-bounds reads in the RPL-Lite implementation of the RPL protocol …

Feb 14, 2024
CVE-2023-50926
7.5 HIGH

Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds read can be caused by an incoming DIO message when using the …

Feb 14, 2024
CVE-2024-25301
7.2 HIGH

Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php.

Feb 14, 2024
CVE-2023-48229
7.0 HIGH

Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds write exists in the driver for IEEE 802.15.4 radios on nRF platforms …

Feb 14, 2024
CVE-2024-24990
7.5 HIGH

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The …

Feb 14, 2024
CVE-2024-24989
7.5 HIGH

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The …

Feb 14, 2024
CVE-2024-24775
7.5 HIGH

When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. …

Feb 14, 2024
CVE-2024-23982
7.5 HIGH

When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This …

Feb 14, 2024
CVE-2024-23979
7.5 HIGH

When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an …

Feb 14, 2024
CVE-2024-23805
7.5 HIGH

Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility and Reporting module, this may occur when the HTTP Analytics …

Feb 14, 2024
CVE-2024-23314
7.5 HIGH

When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions …

Feb 14, 2024
CVE-2024-23308
7.5 HIGH

When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause …

Feb 14, 2024
CVE-2024-23306
7.1 HIGH

A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files. Note: Software versions which have reached End …

Feb 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.