CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42934
5.0 MEDIUM

OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or (with very low probability) …

Oct 9, 2024
CVE-2024-7963
6.4 MEDIUM

The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's multiple shortcodes in all versions up to, and including, …

Oct 9, 2024
CVE-2024-36814
4.9 MEDIUM

An arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary files as root on the underlying Operating System via …

Oct 8, 2024
CVE-2024-47822
4.2 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Access tokens from query strings are not redacted and are potentially exposed …

Oct 8, 2024
CVE-2024-46410
4.8 MEDIUM

PublicCMS V4.0.202406.d was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted script to the Category Managment feature

Oct 8, 2024
CVE-2024-43614
5.5 MEDIUM

Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.

Oct 8, 2024
CVE-2024-43612
6.9 MEDIUM

Power BI Report Server Spoofing Vulnerability

Oct 8, 2024
CVE-2024-43609
6.5 MEDIUM

Microsoft Office Spoofing Vulnerability

Oct 8, 2024
CVE-2024-43604
5.7 MEDIUM

Outlook for Android Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-43603
5.5 MEDIUM

Visual Studio Collector Service Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43585
5.5 MEDIUM

Code Integrity Guard Security Feature Bypass Vulnerability

Oct 8, 2024
CVE-2024-43573
6.5 MEDIUM KEV

Windows MSHTML Platform Spoofing Vulnerability

Oct 8, 2024
CVE-2024-43571
5.6 MEDIUM

Sudo for Windows Spoofing Vulnerability

Oct 8, 2024
CVE-2024-43570
6.4 MEDIUM

Windows Kernel Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-43561
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43559
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43558
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43557
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43555
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43554
5.5 MEDIUM

Windows Kernel-Mode Driver Information Disclosure Vulnerability

Oct 8, 2024
CVE-2024-43547
6.5 MEDIUM

Windows Kerberos Information Disclosure Vulnerability

Oct 8, 2024
CVE-2024-43546
5.6 MEDIUM

Windows Cryptographic Information Disclosure Vulnerability

Oct 8, 2024
CVE-2024-43543
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43542
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43540
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43538
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43537
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43536
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43534
6.5 MEDIUM

Windows Graphics Component Information Disclosure Vulnerability

Oct 8, 2024
CVE-2024-43526
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43525
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43524
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43523
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43520
5.0 MEDIUM

Windows Kernel Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43513
6.4 MEDIUM

BitLocker Security Feature Bypass Vulnerability

Oct 8, 2024
CVE-2024-43512
6.5 MEDIUM

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43508
5.5 MEDIUM

Windows Graphics Component Information Disclosure Vulnerability

Oct 8, 2024
CVE-2024-43500
5.5 MEDIUM

Windows Resilient File System (ReFS) Information Disclosure Vulnerability

Oct 8, 2024
CVE-2024-43481
6.5 MEDIUM

Power BI Report Server Spoofing Vulnerability

Oct 8, 2024
CVE-2024-43480
6.6 MEDIUM

Azure Service Fabric for Linux Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43456
4.8 MEDIUM

Windows Remote Desktop Services Tampering Vulnerability

Oct 8, 2024
CVE-2024-37983
6.7 MEDIUM

Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability

Oct 8, 2024
CVE-2024-37982
6.7 MEDIUM

Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability

Oct 8, 2024
CVE-2024-37979
6.7 MEDIUM

Windows Kernel Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-37976
6.7 MEDIUM

Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability

Oct 8, 2024
CVE-2024-35215
6.2 MEDIUM

NULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 and 7.0 could allow an …

Oct 8, 2024
CVE-2024-9622
5.3 MEDIUM

A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an …

Oct 8, 2024
CVE-2024-9621
5.3 MEDIUM

A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to …

Oct 8, 2024
CVE-2024-9620
5.3 MEDIUM

A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensitive information. An attacker with network access could …

Oct 8, 2024
CVE-2024-9379
6.5 MEDIUM KEV

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL …

Oct 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.