CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28903
6.7 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-28902
5.5 MEDIUM

Windows Remote Access Connection Manager Information Disclosure Vulnerability

Apr 9, 2024
CVE-2024-28901
5.5 MEDIUM

Windows Remote Access Connection Manager Information Disclosure Vulnerability

Apr 9, 2024
CVE-2024-28900
5.5 MEDIUM

Windows Remote Access Connection Manager Information Disclosure Vulnerability

Apr 9, 2024
CVE-2024-28898
6.3 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-28897
6.8 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-26255
5.5 MEDIUM

Windows Remote Access Connection Manager Information Disclosure Vulnerability

Apr 9, 2024
CVE-2024-26253
6.8 MEDIUM

Windows rndismp6.sys Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-26252
6.8 MEDIUM

Windows rndismp6.sys Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-26251
6.8 MEDIUM

Microsoft SharePoint Server Spoofing Vulnerability

Apr 9, 2024
CVE-2024-26250
6.7 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-26234
6.7 MEDIUM

Proxy Driver Spoofing Vulnerability

Apr 9, 2024
CVE-2024-26226
6.5 MEDIUM

Windows Distributed File System (DFS) Information Disclosure Vulnerability

Apr 9, 2024
CVE-2024-26220
5.0 MEDIUM

Windows Mobile Hotspot Information Disclosure Vulnerability

Apr 9, 2024
CVE-2024-26217
5.5 MEDIUM

Windows Remote Access Connection Manager Information Disclosure Vulnerability

Apr 9, 2024
CVE-2024-26209
5.5 MEDIUM

Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

Apr 9, 2024
CVE-2024-26207
5.5 MEDIUM

Windows Remote Access Connection Manager Information Disclosure Vulnerability

Apr 9, 2024
CVE-2024-26193
6.4 MEDIUM

Azure Migrate Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-26183
6.5 MEDIUM

Windows Kerberos Denial of Service Vulnerability

Apr 9, 2024
CVE-2024-26172
5.5 MEDIUM

Windows DWM Core Library Information Disclosure Vulnerability

Apr 9, 2024
CVE-2024-26171
6.7 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-26168
6.8 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-21424
6.5 MEDIUM

Azure Compute Gallery Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-20685
5.9 MEDIUM

Azure Private 5G Core Denial of Service Vulnerability

Apr 9, 2024
CVE-2024-20669
6.7 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-20665
6.1 MEDIUM

BitLocker Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-31868
6.1 MEDIUM

Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal users. This issue affects …

Apr 9, 2024
CVE-2024-31865
6.5 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run …

Apr 9, 2024
CVE-2024-31487
5.9 MEDIUM

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 …

Apr 9, 2024
CVE-2024-23662
5.3 MEDIUM

An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and …

Apr 9, 2024
CVE-2023-48784
6.7 MEDIUM

A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.1 and below, version 7.2.7 and below, 7.0 all versions, 6.4 all versions command …

Apr 9, 2024
CVE-2023-47542
6.7 MEDIUM

A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and below, versions 7.2.4 and below, and 7.0.10 and …

Apr 9, 2024
CVE-2023-47541
6.7 MEDIUM

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 …

Apr 9, 2024
CVE-2023-47540
6.7 MEDIUM

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2.1 through 4.2.6, …

Apr 9, 2024
CVE-2024-28234
4.3 MEDIUM

Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4, it is possible to inject CSS …

Apr 9, 2024
CVE-2024-28190
5.4 MEDIUM

Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, users can inject malicious code in …

Apr 9, 2024
CVE-2024-31544
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Computer Laboratory Management System v1.0 allows attackers to execute arbitrary JavaScript code by including malicious payloads into “remarks”, …

Apr 9, 2024
CVE-2024-31863
5.3 MEDIUM

Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to …

Apr 9, 2024
CVE-2024-31862
5.3 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are …

Apr 9, 2024
CVE-2022-47894
5.3 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin SAP.This issue affects Apache Zeppelin SAP: from 0.8.0 before 0.11.0. As this project is retired, we do not …

Apr 9, 2024
CVE-2021-28656
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue affects Apache Zeppelin Apache Zeppelin …

Apr 9, 2024
CVE-2024-31860
6.5 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that …

Apr 9, 2024
CVE-2024-31369
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.

Apr 9, 2024
CVE-2024-31368
6.5 MEDIUM

Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.

Apr 9, 2024
CVE-2024-30190
6.1 MEDIUM

A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0), SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0), SCALANCE W1788-2 …

Apr 9, 2024
CVE-2024-30189
6.1 MEDIUM

A vulnerability has been identified in SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0) (All versions), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0) (All versions), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0) (All versions), SCALANCE …

Apr 9, 2024
CVE-2023-50821
6.2 MEDIUM

A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC04), SIMATIC WinCC Runtime Professional V17 (All versions < V17 …

Apr 9, 2024
CVE-2024-1664
6.1 MEDIUM

The Responsive Gallery Grid WordPress plugin before 2.3.11 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Apr 9, 2024
CVE-2024-30218
6.5 MEDIUM

The ABAP Application Server of SAP NetWeaver as well as ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by …

Apr 9, 2024
CVE-2024-30217
4.3 MEDIUM

Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, …

Apr 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.