CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-49471
8.8 HIGH

Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus Bar Assistant before version 3.2.0 does not validate a parameter before making a request through Image::make(), which …

Jan 10, 2024
CVE-2023-49427
7.5 HIGH

Buffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remote attackers to cause a denial of service (DoS) via list parameter in SetNetControlList function.

Jan 10, 2024
CVE-2023-48864
7.5 HIGH

SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php.

Jan 10, 2024
CVE-2024-21643
7.1 HIGH

IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's identity. Anyone leveraging the `SignedHttpRequest`protocol …

Jan 10, 2024
CVE-2024-0359
7.3 HIGH

A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the …

Jan 10, 2024
CVE-2024-0352
7.3 HIGH

A vulnerability classified as critical was found in Likeshop up to 2.5.7.20210311. This vulnerability affects the function FileServer::userFormImage of the file server/application/api/controller/File.php of the component …

Jan 9, 2024
CVE-2023-47994
8.8 HIGH

An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service and/or run …

Jan 9, 2024
CVE-2023-47992
8.8 HIGH

An integer overflow vulnerability in FreeImageIO.cpp::_MemoryReadProc in FreeImage 3.18.0 allows attackers to obtain sensitive information, cause a denial-of-service attacks and/or run arbitrary code.

Jan 9, 2024
CVE-2023-37297
8.3 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of …

Jan 9, 2024
CVE-2023-37296
8.3 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack memory corruption via an adjacent network. A successful exploitation of …

Jan 9, 2024
CVE-2023-37295
8.3 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of …

Jan 9, 2024
CVE-2023-37294
8.3 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of …

Jan 9, 2024
CVE-2023-34333
7.8 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference via a local network. A successful exploitation …

Jan 9, 2024
CVE-2023-34332
7.8 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference by a local network. A successful exploitation …

Jan 9, 2024
CVE-2023-7032
7.8 HIGH

A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher privileges by …

Jan 9, 2024
CVE-2024-21325
7.8 HIGH

Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-21318
8.8 HIGH

Microsoft SharePoint Server Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-21312
7.5 HIGH

.NET Framework Denial of Service Vulnerability

Jan 9, 2024
CVE-2024-21310
7.8 HIGH

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-21309
7.8 HIGH

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-21307
7.5 HIGH

Remote Desktop Client Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-20700
7.5 HIGH

Windows Hyper-V Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-20698
7.8 HIGH

Windows Kernel Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-20697
7.3 HIGH

Windows libarchive Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-20696
7.3 HIGH

Windows libarchive Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-20687
7.5 HIGH

Microsoft AllJoyn API Denial of Service Vulnerability

Jan 9, 2024
CVE-2024-20686
7.8 HIGH

Win32k Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-20683
7.8 HIGH

Win32k Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-20682
7.8 HIGH

Windows Cryptographic Services Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-20681
7.8 HIGH

Windows Subsystem for Linux Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-20677
7.8 HIGH

A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX files has been …

Jan 9, 2024
CVE-2024-20676
8.0 HIGH

Azure Storage Mover Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-20674
8.8 HIGH

Windows Kerberos Security Feature Bypass Vulnerability

Jan 9, 2024
CVE-2024-20672
7.5 HIGH

.NET Denial of Service Vulnerability

Jan 9, 2024
CVE-2024-20661
7.5 HIGH

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

Jan 9, 2024
CVE-2024-20658
7.8 HIGH

Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-20657
7.0 HIGH

Windows Group Policy Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-20656
7.8 HIGH

Visual Studio Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-20654
8.0 HIGH

Microsoft ODBC Driver Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-20653
7.8 HIGH

Microsoft Common Log File System Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-20652
8.1 HIGH

Windows HTML Platforms Security Feature Bypass Vulnerability

Jan 9, 2024
CVE-2024-0056
8.7 HIGH

Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability

Jan 9, 2024
CVE-2022-48618
7.0 HIGH KEV

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An …

Jan 9, 2024
CVE-2023-7222
7.2 HIGH

A vulnerability was found in Totolink X2000R 1.0.0-B20221212.1452. It has been declared as critical. This vulnerability affects the function formTmultiAP of the file /bin/boa of …

Jan 9, 2024
CVE-2022-36765
7.0 HIGH

EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. …

Jan 9, 2024
CVE-2022-36764
7.0 HIGH

EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation …

Jan 9, 2024
CVE-2022-36763
7.0 HIGH

EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation …

Jan 9, 2024
CVE-2024-0213
8.2 HIGH

A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause …

Jan 9, 2024
CVE-2024-0206
7.1 HIGH

A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation …

Jan 9, 2024
CVE-2023-5376
8.6 HIGH

An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware version 2024/01.

Jan 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.